<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 03:49:35 +0000</lastBuildDate>
    <item>
      <title>cnvd-2015-03619</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2015-03619</link>
      <description>cnvd-2015-03619</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2015-03619</guid>
    </item>
    <item>
      <title>EUVD-2026-91485</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-91485</link>
      <description>EUVD-2026-91485</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-91485</guid>
    </item>
    <item>
      <title>fkie_cve-2015-2944</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2015-2944</link>
      <description>&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2015-2944</guid>
    </item>
    <item>
      <title>GHSA-rxvx-44w5-44r7 — Improper Neutralization of Input During Web Page Generation in Apache Sling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rxvx-44w5-44r7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.sling:org.apache.sling.api, Maven: org.apache.sling:org.apache.sling.servlets.post&lt;/p&gt;
&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.sling:org.apache.sling.api, Maven: org.apache.sling:org.apache.sling.servlets.post&lt;/p&gt;
&lt;p&gt;Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rxvx-44w5-44r7</guid>
    </item>
    <item>
      <title>gsd-2015-2944</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2015-2944</link>
      <description>gsd-2015-2944</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2015-2944</guid>
    </item>
    <item>
      <title>jvndb-2015-000069</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2015-000069</link>
      <description>&lt;p&gt;Apache Sling is an open source web application framework provided by The Apache Software Foundation.&#13;
Sling API and Servlet Post components included in Apache Sling contain a cross-site scripting vulnerability (CWE-79) in the error page and the generation of the job completion.&#13;
&#13;
MORI Shingo and Toshiharu Sugiyama of DeNA Co., Ltd. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache Sling is an open source web application framework provided by The Apache Software Foundation.&#13;
Sling API and Servlet Post components included in Apache Sling contain a cross-site scripting vulnerability (CWE-79) in the error page and the generation of the job completion.&#13;
&#13;
MORI Shingo and Toshiharu Sugiyama of DeNA Co., Ltd. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2015-000069</guid>
    </item>
  </channel>
</rss>
