<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 19:27:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-235743</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-235743</link>
      <description>EUVD-2026-235743</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-235743</guid>
    </item>
    <item>
      <title>fkie_cve-2025-46347</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46347</link>
      <description>&lt;p&gt;YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of the server. This could potentially be performed unwittingly by a user. This issue has been patched in version 4.5.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of the server. This could potentially be performed unwittingly by a user. This issue has been patched in version 4.5.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-46347</guid>
    </item>
    <item>
      <title>GHSA-88xg-v53p-fpvf — YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-88xg-v53p-fpvf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yeswiki/yeswiki&lt;/p&gt;
&lt;p&gt;### Summary
An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server.&lt;/p&gt;
&lt;p&gt;All testing was performed on a local docker setup running the latest version of the application.&lt;/p&gt;
&lt;p&gt;### PoC
Proof of Concept&lt;/p&gt;
&lt;p&gt;Navigate to `http://localhost:8085/?LookWiki` which allows you to click `Create a new Graphical configuration` where you specify some parameters and then click `Save`.&lt;/p&gt;
&lt;p&gt;![LookWiki](https://github.com/user-attachments/assets/11c638ec-b700-483a-91fb-2d83107c2c69)&lt;/p&gt;
&lt;p&gt;After clicking save, this request is made (most headers removed for clarity):&lt;/p&gt;
&lt;p&gt;```
POST /?api/templates/custom-presets/test.css HTTP/1.1
Host: localhost:8085&lt;/p&gt;
&lt;p&gt;primary-color=%230c5d6a&amp;amp;secondary-color-1=%23d8604c&amp;amp;secondary-color-2=%23d78958&amp;amp;neutral-color=%234e5056&amp;amp;neutral-soft-color=%2357575c&amp;amp;neutral-light-color=%23f2f2f2&amp;amp;main-text-fontsize=17px&amp;amp;main-text-fontfamily=%22Nunito%22%2C+sans-serif&amp;amp;main-title-fontfamily=&amp;#39;Nunito&amp;#39;%2C+sans-serif
```&lt;/p&gt;
&lt;p&gt;This request writes the file `test.css` to disk with the contents (abbreviated)
```
:root {
  --primary-color: #0c5d6a;
  --secondary-color-1: #d8604c;
  --secondary-color-2: #d78958;
  --neutral-color: #4e5056;
  --neutral-soft-color: #57575c;
  --neutral-light-color: #f2f2f2;
  --main-text-fontsize: 17px;
  --main-text-fontfamily: &amp;#34;Nunito&amp;#34;, sans-serif;
  --main-title-fontfamily: &amp;#39;Nunito&amp;#39;, sans-serif;
}
```&lt;/p&gt;
&lt;p&gt;To exploit this, utilize a proxy tool to intercept the the first request and change t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yeswiki/yeswiki&lt;/p&gt;
&lt;p&gt;### Summary
An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server.&lt;/p&gt;
&lt;p&gt;All testing was performed on a local docker setup running the latest version of the application.&lt;/p&gt;
&lt;p&gt;### PoC
Proof of Concept&lt;/p&gt;
&lt;p&gt;Navigate to `http://localhost:8085/?LookWiki` which allows you to click `Create a new Graphical configuration` where you specify some parameters and then click `Save`.&lt;/p&gt;
&lt;p&gt;![LookWiki](https://github.com/user-attachments/assets/11c638ec-b700-483a-91fb-2d83107c2c69)&lt;/p&gt;
&lt;p&gt;After clicking save, this request is made (most headers removed for clarity):&lt;/p&gt;
&lt;p&gt;```
POST /?api/templates/custom-presets/test.css HTTP/1.1
Host: localhost:8085&lt;/p&gt;
&lt;p&gt;primary-color=%230c5d6a&amp;amp;secondary-color-1=%23d8604c&amp;amp;secondary-color-2=%23d78958&amp;amp;neutral-color=%234e5056&amp;amp;neutral-soft-color=%2357575c&amp;amp;neutral-light-color=%23f2f2f2&amp;amp;main-text-fontsize=17px&amp;amp;main-text-fontfamily=%22Nunito%22%2C+sans-serif&amp;amp;main-title-fontfamily=&amp;#39;Nunito&amp;#39;%2C+sans-serif
```&lt;/p&gt;
&lt;p&gt;This request writes the file `test.css` to disk with the contents (abbreviated)
```
:root {
  --primary-color: #0c5d6a;
  --secondary-color-1: #d8604c;
  --secondary-color-2: #d78958;
  --neutral-color: #4e5056;
  --neutral-soft-color: #57575c;
  --neutral-light-color: #f2f2f2;
  --main-text-fontsize: 17px;
  --main-text-fontfamily: &amp;#34;Nunito&amp;#34;, sans-serif;
  --main-title-fontfamily: &amp;#39;Nunito&amp;#39;, sans-serif;
}
```&lt;/p&gt;
&lt;p&gt;To exploit this, utilize a proxy tool to intercept the the first request and change t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-88xg-v53p-fpvf</guid>
    </item>
  </channel>
</rss>
