<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 17:07:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-240021</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-240021</link>
      <description>EUVD-2026-240021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-240021</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27566</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27566</link>
      <description>&lt;p&gt;Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27566</guid>
    </item>
    <item>
      <title>GHSA-w57q-v7qr-v5m7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w57q-v7qr-v5m7</link>
      <description>&lt;p&gt;Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w57q-v7qr-v5m7</guid>
    </item>
    <item>
      <title>jvndb-2025-005050</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2025-005050</link>
      <description>&lt;p&gt;a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below.&#13;
&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;Path traversal (CWE-22)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-27566&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Cross-site scripting (CWE-79)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-32999&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Server-side request forgery (CWE-918)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-36560&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Improper output neutralization for logs (CWE-117)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-41429&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
CVE-2025-27566, CVE-2025-32999&#13;
haidv35 (Dinh Viet Hai) reported these vulnerabilities to the developer and coordinated. After the coordination was completed, haidv35 (Dinh Viet Hai) reported the case to JPCERT/CC to notify users of the solution through JVN.&#13;
&#13;
CVE-2025-36560, CVE-2025-41429&#13;
vcth4nh from VCSLab of Viettel Cyber Security (Vu Chi Thanh) reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below.&#13;
&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;Path traversal (CWE-22)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-27566&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Cross-site scripting (CWE-79)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-32999&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Server-side request forgery (CWE-918)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-36560&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Improper output neutralization for logs (CWE-117)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-41429&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
CVE-2025-27566, CVE-2025-32999&#13;
haidv35 (Dinh Viet Hai) reported these vulnerabilities to the developer and coordinated. After the coordination was completed, haidv35 (Dinh Viet Hai) reported the case to JPCERT/CC to notify users of the solution through JVN.&#13;
&#13;
CVE-2025-36560, CVE-2025-41429&#13;
vcth4nh from VCSLab of Viettel Cyber Security (Vu Chi Thanh) reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2025-005050</guid>
    </item>
  </channel>
</rss>
