<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 18:27:51 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-05133</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-05133</link>
      <description>bdu:2020-05133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-05133</guid>
    </item>
    <item>
      <title>BIT-magento-2020-24408 — Stored XSS in customer address upload feature</title>
      <link>https://cve.radiocsirt.org/vuln/bit-magento-2020-24408</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: magento&lt;/p&gt;
&lt;p&gt;Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: magento&lt;/p&gt;
&lt;p&gt;Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-magento-2020-24408</guid>
    </item>
    <item>
      <title>certfr-2020-avi-648 — De multiples vulnérabilités ont été découvertes dans Magento. Certaines
d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-648</link>
      <description>certfr-2020-avi-648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-648</guid>
    </item>
    <item>
      <title>cnvd-2020-57886</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-57886</link>
      <description>cnvd-2020-57886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-57886</guid>
    </item>
    <item>
      <title>EUVD-2026-183051</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183051</link>
      <description>EUVD-2026-183051</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183051</guid>
    </item>
    <item>
      <title>fkie_cve-2020-24408</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-24408</link>
      <description>&lt;p&gt;Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-24408</guid>
    </item>
    <item>
      <title>GHSA-jxjc-6xmh-h7mg — Magento 2 Community Edition XSS Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxjc-6xmh-h7mg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: magento/community-edition&lt;/p&gt;
&lt;p&gt;Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: magento/community-edition&lt;/p&gt;
&lt;p&gt;Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability could be abused by an unauthenticated attacker to execute XSS attacks against other Magento users. This vulnerability requires a victim to browse to the uploaded file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxjc-6xmh-h7mg</guid>
    </item>
    <item>
      <title>gsd-2020-24408</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-24408</link>
      <description>gsd-2020-24408</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-24408</guid>
    </item>
  </channel>
</rss>
