<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 08:26:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-220971</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-220971</link>
      <description>EUVD-2026-220971</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-220971</guid>
    </item>
    <item>
      <title>fkie_cve-2023-26472</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-26472</link>
      <description>&lt;p&gt;XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for users not having edit right. The issue has been patched in XWiki 14.9, 14.4.6, and 13.10.10. An available workaround is to fix the bug in the page `IconThemesCode.IconThemeSheet` by applying a modification from commit 48caf7491595238af2b531026a614221d5d61f38.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for users not having edit right. The issue has been patched in XWiki 14.9, 14.4.6, and 13.10.10. An available workaround is to fix the bug in the page `IconThemesCode.IconThemeSheet` by applying a modification from commit 48caf7491595238af2b531026a614221d5d61f38.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-26472</guid>
    </item>
    <item>
      <title>GHSA-vwr6-qp4q-2wj7 — XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vwr6-qp4q-2wj7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-icon-ui&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;One can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with the following content:&lt;/p&gt;
&lt;p&gt;```
}}}
{{async async=&amp;#34;true&amp;#34;}}
{{groovy}}
  println(&amp;#34;Hello from Groovy!&amp;#34;)
{{/groovy}}
{{/async}}
{{{
```&lt;/p&gt;
&lt;p&gt;Can be done by creating a new page or even through the user profile for users not having edit right.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in XWiki 14.9, 14.4.6, and 13.10.10.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;An easy workaround is to actually fix the bug in the page `IconThemesCode.IconThemeSheet` by applying the following modification: https://github.com/xwiki/xwiki-platform/commit/48caf7491595238af2b531026a614221d5d61f38#diff-2ec9d716673ee049937219cdb0a92e520f81da14ea84d144504b97ab2bdae243R45&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://jira.xwiki.org/browse/XWIKI-19731&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira](http://jira.xwiki.org)
* Email us at [Security ML](mailto:security@xwiki.org)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-icon-ui&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;One can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with the following content:&lt;/p&gt;
&lt;p&gt;```
}}}
{{async async=&amp;#34;true&amp;#34;}}
{{groovy}}
  println(&amp;#34;Hello from Groovy!&amp;#34;)
{{/groovy}}
{{/async}}
{{{
```&lt;/p&gt;
&lt;p&gt;Can be done by creating a new page or even through the user profile for users not having edit right.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in XWiki 14.9, 14.4.6, and 13.10.10.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;An easy workaround is to actually fix the bug in the page `IconThemesCode.IconThemeSheet` by applying the following modification: https://github.com/xwiki/xwiki-platform/commit/48caf7491595238af2b531026a614221d5d61f38#diff-2ec9d716673ee049937219cdb0a92e520f81da14ea84d144504b97ab2bdae243R45&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://jira.xwiki.org/browse/XWIKI-19731&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira](http://jira.xwiki.org)
* Email us at [Security ML](mailto:security@xwiki.org)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vwr6-qp4q-2wj7</guid>
    </item>
    <item>
      <title>gsd-2023-26472</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-26472</link>
      <description>gsd-2023-26472</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-26472</guid>
    </item>
  </channel>
</rss>
