<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 22:39:05 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-5830</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5830</link>
      <description>EUVD-2026-5830</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5830</guid>
    </item>
    <item>
      <title>fkie_cve-2024-37156</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-37156</link>
      <description>&lt;p&gt;The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS. This vulnerability is fixed in 2.5.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-37156</guid>
    </item>
    <item>
      <title>GHSA-rrvc-c7xg-7cf3 — TokenController formName not sanitized in hidden input</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rrvc-c7xg-7cf3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: sulu/form-bundle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;TokenController get parameter formName not sanitized in returned input field leads to XSS.&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;Create a custom Symfony Request listener which checks for the get value of `form` for the TokenController and if not valid stop the request dispatching and return a error status code.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;_Are there any links users can visit to find out more?_&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: sulu/form-bundle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;TokenController get parameter formName not sanitized in returned input field leads to XSS.&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;Create a custom Symfony Request listener which checks for the get value of `form` for the TokenController and if not valid stop the request dispatching and return a error status code.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;_Are there any links users can visit to find out more?_&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rrvc-c7xg-7cf3</guid>
    </item>
  </channel>
</rss>
