<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:24:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264987</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264987</link>
      <description>EUVD-2026-264987</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264987</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68455</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68455</link>
      <description>&lt;p&gt;Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68455</guid>
    </item>
    <item>
      <title>GHSA-255j-qw47-wjh5 — Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-255j-qw47-wjh5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;Note that attackers must have administrator access to the Craft Control Panel for this to work.&lt;/p&gt;
&lt;p&gt;Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.&lt;/p&gt;
&lt;p&gt;Resources:&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This was reported as a vulnerability in Yii framework on August 7th (https://github.com/yiisoft/yii2/security/advisories/GHSA-gcmh-9pjj-7fp4). The Yii framework team denies responsibility for this (placing the onus on application developers) and hence has not (and seemingly will not) provide a fix at the framework level. Hence, I am reporting this to Craft as I found it to affect the latest (`5.6.0`) version of Craft CMS.&lt;/p&gt;
&lt;p&gt;Leveraging a legitimate but maliciously crafted Yii `Behavior` class, it’s possible to trigger Remote Code Execution (RCE) via Reflection when the tainted `Behavior` is attached to a Yii `Component`, and an event is also fired on the tainted `Component`.&lt;/p&gt;
&lt;p&gt;### Details
This vulnerability is inspired by `CVE-2024-4990` but differs because a legitimate Yii `Behavior` class is used to abuse the magic `__set()` and `__get()` methods to trigger an arbitrary PHP callable, ultimately leading to RCE. As such, this bypasses the mitigations implemente…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;Note that attackers must have administrator access to the Craft Control Panel for this to work.&lt;/p&gt;
&lt;p&gt;Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.&lt;/p&gt;
&lt;p&gt;Resources:&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593&lt;/p&gt;
&lt;p&gt;https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This was reported as a vulnerability in Yii framework on August 7th (https://github.com/yiisoft/yii2/security/advisories/GHSA-gcmh-9pjj-7fp4). The Yii framework team denies responsibility for this (placing the onus on application developers) and hence has not (and seemingly will not) provide a fix at the framework level. Hence, I am reporting this to Craft as I found it to affect the latest (`5.6.0`) version of Craft CMS.&lt;/p&gt;
&lt;p&gt;Leveraging a legitimate but maliciously crafted Yii `Behavior` class, it’s possible to trigger Remote Code Execution (RCE) via Reflection when the tainted `Behavior` is attached to a Yii `Component`, and an event is also fired on the tainted `Component`.&lt;/p&gt;
&lt;p&gt;### Details
This vulnerability is inspired by `CVE-2024-4990` but differs because a legitimate Yii `Behavior` class is used to abuse the magic `__set()` and `__get()` methods to trigger an arbitrary PHP callable, ultimately leading to RCE. As such, this bypasses the mitigations implemente…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-255j-qw47-wjh5</guid>
    </item>
  </channel>
</rss>
