<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:11:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-186125</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-186125</link>
      <description>EUVD-2026-186125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-186125</guid>
    </item>
    <item>
      <title>fkie_cve-2024-45604</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45604</link>
      <description>&lt;p&gt;Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-45604</guid>
    </item>
    <item>
      <title>GHSA-4p75-5p53-65m9 — Contao affected by directory traversal in the file selector widget</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4p75-5p53-65m9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: contao/core-bundle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Back end users can list files outside their file mounts or the document root in the FileSelector widget.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Update to Contao 4.13.49.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Thanks to Jakob Steeg from usd AG for reporting this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: contao/core-bundle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Back end users can list files outside their file mounts or the document root in the FileSelector widget.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Update to Contao 4.13.49.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Thanks to Jakob Steeg from usd AG for reporting this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4p75-5p53-65m9</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2152 — Contao: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2152</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Contao ausnutzen, um beliebigen Code auszuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Contao ausnutzen, um beliebigen Code auszuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2152</guid>
    </item>
  </channel>
</rss>
