<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:07:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-252268</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252268</link>
      <description>EUVD-2026-252268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252268</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58449</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58449</link>
      <description>&lt;p&gt;Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58449</guid>
    </item>
    <item>
      <title>GHSA-vgmm-27fc-vmgp — Maho is Vulnerable to Authenticated Remote Code Execution via File Upload</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vgmm-27fc-vmgp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: mahocommerce/maho&lt;/p&gt;
&lt;p&gt;### Summary
In Maho 25.7.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution&lt;/p&gt;
&lt;p&gt;### Details
An  user with the `Dashboard` and `Catalog\Manage Products` permissions can abuse the product custom options feature to bypass the application’s file upload restrictions.&lt;/p&gt;
&lt;p&gt;When creating a product custom option of type file upload, the user is allowed to define their own extension whitelist. This bypasses the application’s normal enforced whitelist and permits disallowed extensions, including `.php`.&lt;/p&gt;
&lt;p&gt;The file uploaded by the custom option is then written to a predictable location:
```
/public/media/custom_options/&amp;lt;first char of filename&amp;gt;/&amp;lt;second char of filename&amp;gt;/&amp;lt;md5 of file contents&amp;gt;.php
```
Because this path is directly accessible under the application’s webroot, an attacker can then request the uploaded file via HTTP, causing the server to execute the PHP payload.&lt;/p&gt;
&lt;p&gt;### PoC
1. Sign in to the `/admin` dashboard as a staff user. Ensure the user&amp;#39;s role has access to the `Dashboard` and `Catalog\Manage Products` permissions.
2. Navigate to a product catalog listing, for example by clicking on a product linked within the `Most Viewed Products` tab on the dashboard.
&amp;lt;img width=&amp;#34;648&amp;#34; height=&amp;#34;194&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-att…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: mahocommerce/maho&lt;/p&gt;
&lt;p&gt;### Summary
In Maho 25.7.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution&lt;/p&gt;
&lt;p&gt;### Details
An  user with the `Dashboard` and `Catalog\Manage Products` permissions can abuse the product custom options feature to bypass the application’s file upload restrictions.&lt;/p&gt;
&lt;p&gt;When creating a product custom option of type file upload, the user is allowed to define their own extension whitelist. This bypasses the application’s normal enforced whitelist and permits disallowed extensions, including `.php`.&lt;/p&gt;
&lt;p&gt;The file uploaded by the custom option is then written to a predictable location:
```
/public/media/custom_options/&amp;lt;first char of filename&amp;gt;/&amp;lt;second char of filename&amp;gt;/&amp;lt;md5 of file contents&amp;gt;.php
```
Because this path is directly accessible under the application’s webroot, an attacker can then request the uploaded file via HTTP, causing the server to execute the PHP payload.&lt;/p&gt;
&lt;p&gt;### PoC
1. Sign in to the `/admin` dashboard as a staff user. Ensure the user&amp;#39;s role has access to the `Dashboard` and `Catalog\Manage Products` permissions.
2. Navigate to a product catalog listing, for example by clicking on a product linked within the `Most Viewed Products` tab on the dashboard.
&amp;lt;img width=&amp;#34;648&amp;#34; height=&amp;#34;194&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-att…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vgmm-27fc-vmgp</guid>
    </item>
  </channel>
</rss>
