<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:51:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-263437</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263437</link>
      <description>EUVD-2026-263437</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263437</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66284</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66284</link>
      <description>&lt;p&gt;Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66284</guid>
    </item>
    <item>
      <title>GHSA-gvxm-fhfx-8g6r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gvxm-fhfx-8g6r</link>
      <description>&lt;p&gt;Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gvxm-fhfx-8g6r</guid>
    </item>
    <item>
      <title>jvndb-2025-000113</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2025-000113</link>
      <description>&lt;p&gt;GroupSession provided by Japan Total System Co.,Ltd. contains multiple vulnerabilities listed below.&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Stored cross-site scripting (CWE-79) - CVE-2025-53523&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Stored cross-site scripting (CWE-79) - CVE-2025-54407&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Reflected cross-site scripting (CWE-79) - CVE-2025-57883&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Cross-site request forgery (CWE-352) - CVE-2025-58576&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Authorization bypass through user-controlled key (CWE-639) - CVE-2025-61950&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Missing origin validation in webSockets (CWE-1385) - CVE-2025-61987&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;SQL injection (CWE-89) - CVE-2025-62192&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Initialization of a resource with an insecure default (CWE-1188) - CVE-2025-64781&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This can be exploited only when External page display restriction is set as &amp;#34;Do not limit&amp;#34;, as in the initial configurationReflected cross-site scripting (CWE-79) - CVE-2025-65120&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Stored cross-site scripting (CWE-79) - CVE-2025-66284&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
The following people reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2025-53523&#13;
Reporter: Shogo Iyota of GMO Cybersecurity by Ierae&#13;
        Gaku Mochizuki, Tsutomu Aramaki, and Taiga Shirakura of Mitsui Bussan Secure Directions, Inc.&#13;
        Natsumi Furukawa&#13;
&#13;
CVE-2025-54407&#13;
Reporter: Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc.&#13;
&#13;
CVE-2025-57883&#13;
Reporter: Tsuyuki Takumi of Mitsui Bussan Secure Directions, Inc.&#13;
        Ryo Sato&#13;
&#13;
CVE-2025-58576&#13;
Rep…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GroupSession provided by Japan Total System Co.,Ltd. contains multiple vulnerabilities listed below.&#13;
&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Stored cross-site scripting (CWE-79) - CVE-2025-53523&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Stored cross-site scripting (CWE-79) - CVE-2025-54407&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Reflected cross-site scripting (CWE-79) - CVE-2025-57883&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Cross-site request forgery (CWE-352) - CVE-2025-58576&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Authorization bypass through user-controlled key (CWE-639) - CVE-2025-61950&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Missing origin validation in webSockets (CWE-1385) - CVE-2025-61987&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;SQL injection (CWE-89) - CVE-2025-62192&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Initialization of a resource with an insecure default (CWE-1188) - CVE-2025-64781&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;This can be exploited only when External page display restriction is set as &amp;#34;Do not limit&amp;#34;, as in the initial configurationReflected cross-site scripting (CWE-79) - CVE-2025-65120&amp;lt;/li&amp;gt;&#13;
&amp;lt;li&amp;gt;Stored cross-site scripting (CWE-79) - CVE-2025-66284&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&#13;
The following people reported these vulnerabilities to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2025-53523&#13;
Reporter: Shogo Iyota of GMO Cybersecurity by Ierae&#13;
        Gaku Mochizuki, Tsutomu Aramaki, and Taiga Shirakura of Mitsui Bussan Secure Directions, Inc.&#13;
        Natsumi Furukawa&#13;
&#13;
CVE-2025-54407&#13;
Reporter: Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc.&#13;
&#13;
CVE-2025-57883&#13;
Reporter: Tsuyuki Takumi of Mitsui Bussan Secure Directions, Inc.&#13;
        Ryo Sato&#13;
&#13;
CVE-2025-58576&#13;
Rep…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2025-000113</guid>
    </item>
  </channel>
</rss>
