<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 08:43:04 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-162205</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-162205</link>
      <description>EUVD-2026-162205</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-162205</guid>
    </item>
    <item>
      <title>fkie_cve-2024-45406</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45406</link>
      <description>&lt;p&gt;Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-45406</guid>
    </item>
    <item>
      <title>GHSA-28h4-788g-rh42 — Craft CMS vulnerable to stored XSS in breadcrumb list and title fields</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-28h4-788g-rh42</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;### Summary
Multiple Stored XSS can be triggered by the breadcrumb list and title fields with user input.&lt;/p&gt;
&lt;p&gt;### Details
1. In the **/admin/categories** page, category title isn&amp;#39;t sanitized and triggered xss.
2. In the category edit page under the **/admin/categories/**, category title in breadcrumb list isn&amp;#39;t sanitized and triggered xss.
3. In the **/admin/entries** page, entry title isn&amp;#39;t sanitized and triggered xss.
4. In the entry edit page under the **/admin/entries/**, entry title in breadcrumb list isn&amp;#39;t sanitized and triggered xss.
5. In the **/admin/myaccount** and pages under it, username or full name in breadcrumb list isn&amp;#39;t sanitized and triggered xss.&lt;/p&gt;
&lt;p&gt;### Impact
Malicious users can tamper with the control panel.&lt;/p&gt;
&lt;p&gt;### PoC
#### 1. In the **/admin/categories** page, category title isn&amp;#39;t sanitized and triggered xss.
```
1. Access to the Settings -&amp;gt; Categories ( /admin/settings/categories )
2. Create new category group
3. Access to the Categories page ( /admin/categories/ )
4. Push the New category button
5. Input the Title column : xss&amp;lt;script&amp;gt;alert(&amp;#39;xss&amp;#39;)&amp;lt;/script&amp;gt;
6. Push the Create Category or Save button
7. Access to the Categories page again and it triggers xss
``` 
![image](https://github.com/craftcms/cms/assets/83068208/a1b2890e-731b-4fc4-b189-26591f4486fd)
![image](https://github.com/craftcms/cms/assets/83068208/4e0f35c7-fbb0-4d38-a0b5-9e28750ff706)
![image](https://github.com/craftcms/cms/assets/83068208/e046b9db-d83c-4f81-ad91-165c5afedeb9)&lt;/p&gt;
&lt;p&gt;#### 2. In the ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;### Summary
Multiple Stored XSS can be triggered by the breadcrumb list and title fields with user input.&lt;/p&gt;
&lt;p&gt;### Details
1. In the **/admin/categories** page, category title isn&amp;#39;t sanitized and triggered xss.
2. In the category edit page under the **/admin/categories/**, category title in breadcrumb list isn&amp;#39;t sanitized and triggered xss.
3. In the **/admin/entries** page, entry title isn&amp;#39;t sanitized and triggered xss.
4. In the entry edit page under the **/admin/entries/**, entry title in breadcrumb list isn&amp;#39;t sanitized and triggered xss.
5. In the **/admin/myaccount** and pages under it, username or full name in breadcrumb list isn&amp;#39;t sanitized and triggered xss.&lt;/p&gt;
&lt;p&gt;### Impact
Malicious users can tamper with the control panel.&lt;/p&gt;
&lt;p&gt;### PoC
#### 1. In the **/admin/categories** page, category title isn&amp;#39;t sanitized and triggered xss.
```
1. Access to the Settings -&amp;gt; Categories ( /admin/settings/categories )
2. Create new category group
3. Access to the Categories page ( /admin/categories/ )
4. Push the New category button
5. Input the Title column : xss&amp;lt;script&amp;gt;alert(&amp;#39;xss&amp;#39;)&amp;lt;/script&amp;gt;
6. Push the Create Category or Save button
7. Access to the Categories page again and it triggers xss
``` 
![image](https://github.com/craftcms/cms/assets/83068208/a1b2890e-731b-4fc4-b189-26591f4486fd)
![image](https://github.com/craftcms/cms/assets/83068208/4e0f35c7-fbb0-4d38-a0b5-9e28750ff706)
![image](https://github.com/craftcms/cms/assets/83068208/e046b9db-d83c-4f81-ad91-165c5afedeb9)&lt;/p&gt;
&lt;p&gt;#### 2. In the ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-28h4-788g-rh42</guid>
    </item>
  </channel>
</rss>
