<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:46:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-03936</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03936</link>
      <description>bdu:2020-03936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03936</guid>
    </item>
    <item>
      <title>BIT-wordpress-2020-11026 — Specially crafted filenames in WordPress leading to XSS</title>
      <link>https://cve.radiocsirt.org/vuln/bit-wordpress-2020-11026</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wordpress&lt;/p&gt;
&lt;p&gt;In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wordpress&lt;/p&gt;
&lt;p&gt;In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-wordpress-2020-11026</guid>
    </item>
    <item>
      <title>EUVD-2026-40262</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40262</link>
      <description>EUVD-2026-40262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40262</guid>
    </item>
    <item>
      <title>fkie_cve-2020-11026</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11026</link>
      <description>&lt;p&gt;In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-11026</guid>
    </item>
    <item>
      <title>gsd-2020-11026</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-11026</link>
      <description>gsd-2020-11026</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-11026</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-11026</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11026</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: wordpress, Ubuntu:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress, Ubuntu:25.10: wordpress, Ubuntu:26.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: wordpress, Ubuntu:18.04:LTS: wordpress, Ubuntu:20.04:LTS: wordpress, Ubuntu:22.04:LTS: wordpress, Ubuntu:24.04:LTS: wordpress, Ubuntu:25.10: wordpress, Ubuntu:26.04:LTS: wordpress&lt;/p&gt;
&lt;p&gt;In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11026</guid>
    </item>
  </channel>
</rss>
