<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:06:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343430</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343430</link>
      <description>EUVD-2026-343430</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343430</guid>
    </item>
    <item>
      <title>fkie_cve-2026-21662</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21662</link>
      <description>&lt;p&gt;Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.&lt;/p&gt;
&lt;p&gt;This issue affects FM Systems Employee: before 2025.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.&lt;/p&gt;
&lt;p&gt;This issue affects FM Systems Employee: before 2025.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-21662</guid>
    </item>
    <item>
      <title>GHSA-9m8h-rcg4-v896</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9m8h-rcg4-v896</link>
      <description>&lt;p&gt;Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.&lt;/p&gt;
&lt;p&gt;This issue affects FM Systems Employee: before 2025.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.&lt;/p&gt;
&lt;p&gt;This issue affects FM Systems Employee: before 2025.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9m8h-rcg4-v896</guid>
    </item>
    <item>
      <title>ICSA-26-211-02 — Johnson Controls OpenBlue Employee</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-211-02</link>
      <description>&lt;p&gt;The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. Stored XSS occurs when the application improperly handles user input and stores malicious JavaScript code within its database. This script is then rendered and executed whenever another user accesses the compromised page. Unlike reflected XSS, persistent XSS is particularly dangerous because the payload remains active until it is manually removed from the system. HTML injection occurs when user-controlled input is embedded into web pages without proper encoding or sanitization, allowing attackers to inject arbitrary HTML markup. This vulnerability enables attackers to manipulate the Document Object Model (DOM) structure and alter the visual presentation of web content. Unlike Cross-Site Scripting (XSS), HTML injection typically involves static HTML content rather than executable JavaScript, though it can serve as a stepping stone to more severe attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The application does not adequately restrict the types of files that can be uploaded, allowing an attacker to submit files with dangerous content types. Uploaded files may be stored in predictable locations and could be leveraged for further exploitation against the application or its users. Stored XSS occurs when the application improperly handles user input and stores malicious JavaScript code within its database. This script is then rendered and executed whenever another user accesses the compromised page. Unlike reflected XSS, persistent XSS is particularly dangerous because the payload remains active until it is manually removed from the system. HTML injection occurs when user-controlled input is embedded into web pages without proper encoding or sanitization, allowing attackers to inject arbitrary HTML markup. This vulnerability enables attackers to manipulate the Document Object Model (DOM) structure and alter the visual presentation of web content. Unlike Cross-Site Scripting (XSS), HTML injection typically involves static HTML content rather than executable JavaScript, though it can serve as a stepping stone to more severe attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-211-02</guid>
    </item>
  </channel>
</rss>
