<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:01:45 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-367904</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-367904</link>
      <description>EUVD-2026-367904</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-367904</guid>
    </item>
    <item>
      <title>fkie_cve-2023-50459</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-50459</link>
      <description>&lt;p&gt;An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-50459</guid>
    </item>
    <item>
      <title>GHSA-4xp5-hr35-84cx — Broken Access Control in extension "femanager"</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4xp5-hr35-84cx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: in2code/femanager&lt;/p&gt;
&lt;p&gt;The extension fails to check access permissions for the edit user component. An authenticated frontend user can use the vulnerability to either edit data of various frontend users or to delete various frontend user accounts.&lt;/p&gt;
&lt;p&gt;Another missing access check in the backend module of the extensions allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser and resendUserConfirmation) for any frontend user in the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: in2code/femanager&lt;/p&gt;
&lt;p&gt;The extension fails to check access permissions for the edit user component. An authenticated frontend user can use the vulnerability to either edit data of various frontend users or to delete various frontend user accounts.&lt;/p&gt;
&lt;p&gt;Another missing access check in the backend module of the extensions allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser and resendUserConfirmation) for any frontend user in the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4xp5-hr35-84cx</guid>
    </item>
    <item>
      <title>gsd-2023-50459</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-50459</link>
      <description>gsd-2023-50459</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-50459</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3144 — TYPO3 Extensions: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3144</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in verschiedenen TYPO3 Extensions ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen und beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in verschiedenen TYPO3 Extensions ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen und beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3144</guid>
    </item>
  </channel>
</rss>
