<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:53:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-372936</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372936</link>
      <description>EUVD-2026-372936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372936</guid>
    </item>
    <item>
      <title>fkie_cve-2026-94373</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-94373</link>
      <description>&lt;p&gt;MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML &amp;lt;option&amp;gt; elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as the option text (value.text or value) is interpreted as live DOM content rather than plain text. An attacker who can influence the data rendered in the contextual menu can inject arbitrary HTML or JavaScript that executes in the victim&amp;#39;s browser within the MISP application origin. This may allow session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.&lt;/p&gt;
&lt;p&gt;Version affected: &amp;lt;2.5.47&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML &amp;lt;option&amp;gt; elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as the option text (value.text or value) is interpreted as live DOM content rather than plain text. An attacker who can influence the data rendered in the contextual menu can inject arbitrary HTML or JavaScript that executes in the victim&amp;#39;s browser within the MISP application origin. This may allow session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.&lt;/p&gt;
&lt;p&gt;Version affected: &amp;lt;2.5.47&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-94373</guid>
    </item>
    <item>
      <title>GHSA-6m7x-x7f7-6wjc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6m7x-x7f7-6wjc</link>
      <description>&lt;p&gt;MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML &amp;lt;option&amp;gt; elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as the option text (value.text or value) is interpreted as live DOM content rather than plain text. An attacker who can influence the data rendered in the contextual menu can inject arbitrary HTML or JavaScript that executes in the victim&amp;#39;s browser within the MISP application origin. This may allow session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.&lt;/p&gt;
&lt;p&gt;Version affected: &amp;lt;2.5.47&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML &amp;lt;option&amp;gt; elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML markup, any untrusted string supplied as the option text (value.text or value) is interpreted as live DOM content rather than plain text. An attacker who can influence the data rendered in the contextual menu can inject arbitrary HTML or JavaScript that executes in the victim&amp;#39;s browser within the MISP application origin. This may allow session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user.&lt;/p&gt;
&lt;p&gt;Version affected: &amp;lt;2.5.47&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6m7x-x7f7-6wjc</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3490 — MISP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3490</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Daten zu manipulieren oder offenzulegen sowie Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Daten zu manipulieren oder offenzulegen sowie Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3490</guid>
    </item>
  </channel>
</rss>
