<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 19:17:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-05357</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-05357</link>
      <description>bdu:2025-05357</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-05357</guid>
    </item>
    <item>
      <title>EUVD-2026-235939</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-235939</link>
      <description>EUVD-2026-235939</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-235939</guid>
    </item>
    <item>
      <title>fkie_cve-2025-32970</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32970</link>
      <description>&lt;p&gt;XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-32970</guid>
    </item>
    <item>
      <title>GHSA-pjhg-9wr9-rj96 — org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pjhg-9wr9-rj96</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-wysiwyg-api&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirect to any URL. To reproduce, open `&amp;lt;xwiki-host&amp;gt;/xwiki/bin/view/Main/?foo=bar&amp;amp;foo_syntax=invalid&amp;amp;RequiresHTMLConversion=foo&amp;amp;xerror=https://www.example.com/` where `&amp;lt;xwiki-host&amp;gt;` is the URL of your XWiki installation.&lt;/p&gt;
&lt;p&gt;### Patches
This bug has been fixed in XWiki 15.10.13, 16.4.4 and 16.8.0 by validating the domain of the redirect URL against the configured safe domains and the current request&amp;#39;s domain.&lt;/p&gt;
&lt;p&gt;### Workarounds
A web application firewall could be configured to reject requests with the `xerror` parameter as from our analysis this parameter isn&amp;#39;t used anymore. For requests with the `RequiresHTMLConversion` parameter set, the referrer URL should be checked if it points to the XWiki installation. Apart from that, we&amp;#39;re not aware of any workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.xwiki.platform:xwiki-platform-wysiwyg-api&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirect to any URL. To reproduce, open `&amp;lt;xwiki-host&amp;gt;/xwiki/bin/view/Main/?foo=bar&amp;amp;foo_syntax=invalid&amp;amp;RequiresHTMLConversion=foo&amp;amp;xerror=https://www.example.com/` where `&amp;lt;xwiki-host&amp;gt;` is the URL of your XWiki installation.&lt;/p&gt;
&lt;p&gt;### Patches
This bug has been fixed in XWiki 15.10.13, 16.4.4 and 16.8.0 by validating the domain of the redirect URL against the configured safe domains and the current request&amp;#39;s domain.&lt;/p&gt;
&lt;p&gt;### Workarounds
A web application firewall could be configured to reject requests with the `xerror` parameter as from our analysis this parameter isn&amp;#39;t used anymore. For requests with the `RequiresHTMLConversion` parameter set, the referrer URL should be checked if it points to the XWiki installation. Apart from that, we&amp;#39;re not aware of any workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pjhg-9wr9-rj96</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0898 — xwiki: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0898</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um falsche Informationen darzustellen, einen Denial-of-Service auszulösen, Benutzerrechte zu erlangen oder Cross-Site-Scripting durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um falsche Informationen darzustellen, einen Denial-of-Service auszulösen, Benutzerrechte zu erlangen oder Cross-Site-Scripting durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0898</guid>
    </item>
  </channel>
</rss>
