<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:38:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-111122</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-111122</link>
      <description>EUVD-2026-111122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-111122</guid>
    </item>
    <item>
      <title>fkie_cve-2012-2399</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2012-2399</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2012-2399</guid>
    </item>
    <item>
      <title>GHSA-m6ch-qxrg-ggw6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m6ch-qxrg-ggw6</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m6ch-qxrg-ggw6</guid>
    </item>
    <item>
      <title>gsd-2012-2399</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2012-2399</link>
      <description>gsd-2012-2399</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2012-2399</guid>
    </item>
    <item>
      <title>jvndb-2012-002110</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2012-002110</link>
      <description>&lt;p&gt;WordPress contains a cross-site scripting vulnerability due to an issue in the SWFUpload library.&#13;
&#13;
ma.la reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WordPress contains a cross-site scripting vulnerability due to an issue in the SWFUpload library.&#13;
&#13;
ma.la reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2012-002110</guid>
    </item>
  </channel>
</rss>
