<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:00:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-01033</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01033</link>
      <description>bdu:2022-01033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01033</guid>
    </item>
    <item>
      <title>EUVD-2026-234405</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234405</link>
      <description>EUVD-2026-234405</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234405</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23655</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23655</link>
      <description>&lt;p&gt;Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private keys. Users are advised to upgrade their installations to build 474 or v1.1.10. The only known workaround is to manually apply the patch (e3b455ad587282f0fbcb7763c6d9c3d000ca1e6a) which adds server signature validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private keys. Users are advised to upgrade their installations to build 474 or v1.1.10. The only known workaround is to manually apply the patch (e3b455ad587282f0fbcb7763c6d9c3d000ca1e6a) which adds server signature validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23655</guid>
    </item>
    <item>
      <title>GHSA-53m6-44rc-h2q5 — Missing server signature validation in OctoberCMS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-53m6-44rc-h2q5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: october/system&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory affects authors of plugins and themes listed on the October CMS marketplace where an end-user will inadvertently expose authors to potential financial loss by entering their private license key into a compromised server.&lt;/p&gt;
&lt;p&gt;It has been disclosed that a project fork of October CMS v1.0 is using a compromised gateway to access the October CMS marketplace service. The compromised gateway captures the personal/business information of users and authors, including private source code files. It was also disclosed that captured plugin files are freely redistributed to other users without authorization.&lt;/p&gt;
&lt;p&gt;1. End-users are provided with a forked version of October CMS v1.0. The provided software is modified to use a compromised gateway server.&lt;/p&gt;
&lt;p&gt;2. The user is instructed to enter their October CMS license key into the administration panel to access the October CMS marketplace. The key is sent to the compromised server while appearing to access the genuine October CMS gateway server.&lt;/p&gt;
&lt;p&gt;3. The compromised gateway server uses a &amp;#34;man in the middle&amp;#34; mechanism that captures information while forwarding the request to the genuine October CMS gateway and relaying the response back to the client.&lt;/p&gt;
&lt;p&gt;4. The compromised gateway server stores the license key and other information about the user account including client name, email address and contents of purchased plugins and privately uploaded plugin files.&lt;/p&gt;
&lt;p&gt;5. The stored plugin files are made available to other users of the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: october/system&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This advisory affects authors of plugins and themes listed on the October CMS marketplace where an end-user will inadvertently expose authors to potential financial loss by entering their private license key into a compromised server.&lt;/p&gt;
&lt;p&gt;It has been disclosed that a project fork of October CMS v1.0 is using a compromised gateway to access the October CMS marketplace service. The compromised gateway captures the personal/business information of users and authors, including private source code files. It was also disclosed that captured plugin files are freely redistributed to other users without authorization.&lt;/p&gt;
&lt;p&gt;1. End-users are provided with a forked version of October CMS v1.0. The provided software is modified to use a compromised gateway server.&lt;/p&gt;
&lt;p&gt;2. The user is instructed to enter their October CMS license key into the administration panel to access the October CMS marketplace. The key is sent to the compromised server while appearing to access the genuine October CMS gateway server.&lt;/p&gt;
&lt;p&gt;3. The compromised gateway server uses a &amp;#34;man in the middle&amp;#34; mechanism that captures information while forwarding the request to the genuine October CMS gateway and relaying the response back to the client.&lt;/p&gt;
&lt;p&gt;4. The compromised gateway server stores the license key and other information about the user account including client name, email address and contents of purchased plugins and privately uploaded plugin files.&lt;/p&gt;
&lt;p&gt;5. The stored plugin files are made available to other users of the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-53m6-44rc-h2q5</guid>
    </item>
    <item>
      <title>gsd-2022-23655</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23655</link>
      <description>gsd-2022-23655</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23655</guid>
    </item>
  </channel>
</rss>
