<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 23:24:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-13871</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-13871</link>
      <description>EUVD-2026-13871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-13871</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23810</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23810</link>
      <description>&lt;p&gt;Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23810</guid>
    </item>
    <item>
      <title>GHSA-xx3c-ww24-2pgq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xx3c-ww24-2pgq</link>
      <description>&lt;p&gt;Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xx3c-ww24-2pgq</guid>
    </item>
    <item>
      <title>gsd-2022-23810</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23810</link>
      <description>gsd-2022-23810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23810</guid>
    </item>
    <item>
      <title>jvndb-2022-000014</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2022-000014</link>
      <description>&lt;p&gt;a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below. &#13;
* Cross-site scripting (CWE-79) - CVE-2022-24374&#13;
* Cross-site scripting (CWE-79) - CVE-2022-23916&#13;
* Template injection (CWE-1336) - CVE-2022-23810&#13;
* Authentication bypass (CWE-291) - CVE-2022-21142&#13;
&#13;
CVE-2022-24374&#13;
iwama yuu of Secure Sky Technology Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2022-23916&#13;
Masashi Yamane of LAC Co., Ltd. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2022-23810, CVE-2022-21142&#13;
hibiki moriyama of STNet, Incorporated reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below. &#13;
* Cross-site scripting (CWE-79) - CVE-2022-24374&#13;
* Cross-site scripting (CWE-79) - CVE-2022-23916&#13;
* Template injection (CWE-1336) - CVE-2022-23810&#13;
* Authentication bypass (CWE-291) - CVE-2022-21142&#13;
&#13;
CVE-2022-24374&#13;
iwama yuu of Secure Sky Technology Inc. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2022-23916&#13;
Masashi Yamane of LAC Co., Ltd. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2022-23810, CVE-2022-21142&#13;
hibiki moriyama of STNet, Incorporated reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2022-000014</guid>
    </item>
  </channel>
</rss>
