<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:26:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-240079</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-240079</link>
      <description>EUVD-2026-240079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-240079</guid>
    </item>
    <item>
      <title>fkie_cve-2025-32999</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32999</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges.  If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges.  If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-32999</guid>
    </item>
    <item>
      <title>GHSA-8wqw-fgqf-9mf2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8wqw-fgqf-9mf2</link>
      <description>&lt;p&gt;Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges.  If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges.  If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8wqw-fgqf-9mf2</guid>
    </item>
    <item>
      <title>jvndb-2025-005050</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2025-005050</link>
      <description>&lt;p&gt;a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below.&#13;
&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;Path traversal (CWE-22)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-27566&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Cross-site scripting (CWE-79)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-32999&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Server-side request forgery (CWE-918)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-36560&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Improper output neutralization for logs (CWE-117)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-41429&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
CVE-2025-27566, CVE-2025-32999&#13;
haidv35 (Dinh Viet Hai) reported these vulnerabilities to the developer and coordinated. After the coordination was completed, haidv35 (Dinh Viet Hai) reported the case to JPCERT/CC to notify users of the solution through JVN.&#13;
&#13;
CVE-2025-36560, CVE-2025-41429&#13;
vcth4nh from VCSLab of Viettel Cyber Security (Vu Chi Thanh) reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;a-blog cms provided by appleple inc. contains multiple vulnerabilities listed below.&#13;
&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;Path traversal (CWE-22)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-27566&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Cross-site scripting (CWE-79)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;CVE-2025-32999&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges&amp;lt;/li&amp;gt;&#13;
&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Server-side request forgery (CWE-918)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-36560&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
&amp;lt;li&amp;gt;Improper output neutralization for logs (CWE-117)&amp;lt;/li&amp;gt;&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;CVE-2025-41429&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
&#13;
CVE-2025-27566, CVE-2025-32999&#13;
haidv35 (Dinh Viet Hai) reported these vulnerabilities to the developer and coordinated. After the coordination was completed, haidv35 (Dinh Viet Hai) reported the case to JPCERT/CC to notify users of the solution through JVN.&#13;
&#13;
CVE-2025-36560, CVE-2025-41429&#13;
vcth4nh from VCSLab of Viettel Cyber Security (Vu Chi Thanh) reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2025-005050</guid>
    </item>
  </channel>
</rss>
