<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:58:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-01389</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01389</link>
      <description>bdu:2022-01389</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01389</guid>
    </item>
    <item>
      <title>BIT-magento-2021-36023 — Magento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/bit-magento-2021-36023</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: magento&lt;/p&gt;
&lt;p&gt;Magento Commerce versions 2.4.2 (and earlier), 2.4.2 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: magento&lt;/p&gt;
&lt;p&gt;Magento Commerce versions 2.4.2 (and earlier), 2.4.2 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-magento-2021-36023</guid>
    </item>
    <item>
      <title>certfr-2021-avi-609 — De multiples vulnérabilités ont été découvertes dans Magento. Certaines
d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-609</link>
      <description>certfr-2021-avi-609</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-609</guid>
    </item>
    <item>
      <title>EUVD-2026-219734</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-219734</link>
      <description>EUVD-2026-219734</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-219734</guid>
    </item>
    <item>
      <title>fkie_cve-2021-36023</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-36023</link>
      <description>&lt;p&gt;Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-36023</guid>
    </item>
    <item>
      <title>GHSA-8cjg-f53m-8m9q — Magento XML Injection vulnerability in the Widgets Update Layout</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8cjg-f53m-8m9q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: magento/project-community-edition, Packagist: magento/community-edition&lt;/p&gt;
&lt;p&gt;Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: magento/project-community-edition, Packagist: magento/community-edition&lt;/p&gt;
&lt;p&gt;Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8cjg-f53m-8m9q</guid>
    </item>
    <item>
      <title>gsd-2021-36023</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-36023</link>
      <description>gsd-2021-36023</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-36023</guid>
    </item>
  </channel>
</rss>
