<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:13:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-250400</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-250400</link>
      <description>EUVD-2026-250400</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-250400</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55744</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55744</link>
      <description>&lt;p&gt;UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55744</guid>
    </item>
    <item>
      <title>GHSA-287x-6r2h-f9mw — UnoPim vulnerable to CSRF on Product edit feature and creation of other types</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-287x-6r2h-f9mw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: unopim/unopim&lt;/p&gt;
&lt;p&gt;### Summary
Some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status   | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | `X-XSRF-TOKEN` header used |
| GET | /admin/catalog/products/copy/{id}| Vulnerable :x: | Missing `X-XSRF-TOKEN` header or similar protection |
| POST | /admin/catalog/products/edit/{id}| Vulnerable :x: | Missing `X-XSRF-TOKEN` header or similar protection |
| POST | /admin/settings/users/create | Not Vulnerable :white_check_mark: | `X-XSRF-TOKEN` header used |&lt;/p&gt;
&lt;p&gt;The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
```
/admin/catalog/categories/create
/admin/catalog/categories/edit/{id}
/admin/catalog/category-fields/create
/admin/catalog/category-fields/edit/{id}
/admin/catalog/attributes/create
/admin/catalog/attributes/edit/{id}
```&lt;/p&gt;
&lt;p&gt;### Details
CSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn&amp;#39;t need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either `application/x-www-form-urlencoded` or `multipart/form-data` so we can say this is a `Simple request` ( doesn&amp;#39;t need preflight request ).  The cookies are s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: unopim/unopim&lt;/p&gt;
&lt;p&gt;### Summary
Some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status   | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | `X-XSRF-TOKEN` header used |
| GET | /admin/catalog/products/copy/{id}| Vulnerable :x: | Missing `X-XSRF-TOKEN` header or similar protection |
| POST | /admin/catalog/products/edit/{id}| Vulnerable :x: | Missing `X-XSRF-TOKEN` header or similar protection |
| POST | /admin/settings/users/create | Not Vulnerable :white_check_mark: | `X-XSRF-TOKEN` header used |&lt;/p&gt;
&lt;p&gt;The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
```
/admin/catalog/categories/create
/admin/catalog/categories/edit/{id}
/admin/catalog/category-fields/create
/admin/catalog/category-fields/edit/{id}
/admin/catalog/attributes/create
/admin/catalog/attributes/edit/{id}
```&lt;/p&gt;
&lt;p&gt;### Details
CSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn&amp;#39;t need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either `application/x-www-form-urlencoded` or `multipart/form-data` so we can say this is a `Simple request` ( doesn&amp;#39;t need preflight request ).  The cookies are s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-287x-6r2h-f9mw</guid>
    </item>
  </channel>
</rss>
