<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 19:08:30 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-55704</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-55704</link>
      <description>cnvd-2022-55704</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-55704</guid>
    </item>
    <item>
      <title>EUVD-2026-11930</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-11930</link>
      <description>EUVD-2026-11930</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-11930</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1756</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1756</link>
      <description>&lt;p&gt;The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER[&amp;#39;REQUEST_URI&amp;#39;] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER[&amp;#39;REQUEST_URI&amp;#39;] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1756</guid>
    </item>
    <item>
      <title>GHSA-mg6c-vwvq-75r2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mg6c-vwvq-75r2</link>
      <description>&lt;p&gt;The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER[&amp;#39;REQUEST_URI&amp;#39;] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER[&amp;#39;REQUEST_URI&amp;#39;] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mg6c-vwvq-75r2</guid>
    </item>
    <item>
      <title>gsd-2022-1756</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1756</link>
      <description>gsd-2022-1756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1756</guid>
    </item>
    <item>
      <title>jvndb-2022-000057</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2022-000057</link>
      <description>&lt;p&gt;WordPress Plugin &amp;#34;Newsletter&amp;#34; provided by Stefano Lissa &amp;amp; The Newsletter Team contains a cross-site scripting vulnerability (CWE-79).&#13;
&#13;
Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WordPress Plugin &amp;#34;Newsletter&amp;#34; provided by Stefano Lissa &amp;amp; The Newsletter Team contains a cross-site scripting vulnerability (CWE-79).&#13;
&#13;
Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2022-000057</guid>
    </item>
  </channel>
</rss>
