<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:31:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267143</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267143</link>
      <description>EUVD-2026-267143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267143</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23476</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23476</link>
      <description>&lt;p&gt;FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig&amp;#39;s | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered without sanitization. This vulnerability is fixed in 2025.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig&amp;#39;s | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered without sanitization. This vulnerability is fixed in 2025.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23476</guid>
    </item>
    <item>
      <title>GHSA-g6w2-q45f-xrp4 — FacturaScripts is Vulnerable to Reflected XSS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g6w2-q45f-xrp4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: facturascripts/facturascripts&lt;/p&gt;
&lt;p&gt;# Reflected XSS via SQL Error Messages&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A reflected XSS bug has been found in FacturaScripts. The problem is in how error messages get displayed - it&amp;#39;s using Twig&amp;#39;s `| raw` filter which skips HTML escaping. When a database error is triggered (like passing a string where an integer is expected), the error message includes all input and gets rendered without sanitization.&lt;/p&gt;
&lt;p&gt;Attackers can use this to phish credentials from other users since HttpOnly is set on cookies (so stealing cookies directly won&amp;#39;t work, but attackers can inject a fake login form).&lt;/p&gt;
&lt;p&gt;**CVSS 6.1 (Medium-High)**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## What was Found&lt;/p&gt;
&lt;p&gt;### Where the bug exists in the code:&lt;/p&gt;
&lt;p&gt;`Core/View/Macro/Utils.html.twig`, line 27:&lt;/p&gt;
&lt;p&gt;```twig
{% for item in messages %}
    &amp;lt;div&amp;gt;{{ item.message | raw }}&amp;lt;/div&amp;gt;
{% endfor %}
```&lt;/p&gt;
&lt;p&gt;That `| raw` is the problem. It tells Twig not to escape anything.&lt;/p&gt;
&lt;p&gt;### How it works&lt;/p&gt;
&lt;p&gt;So here&amp;#39;s what happens:&lt;/p&gt;
&lt;p&gt;1. Hhit `/EditProducto?code=&amp;lt;svg onload=alert(1)&amp;gt; or &amp;lt;img src=x onerror=alert(1)&amp;gt;`
2. The app tries to look up a product with that &amp;#34;code&amp;#34;
3. PostgreSQL throws an error because `&amp;lt;svg onload=alert(1)&amp;gt;` isn&amp;#39;t a valid integer
4. The error goes something like:   ```
   ERROR: invalid input syntax for type integer: &amp;#34;&amp;lt;svg onload=alert(1)&amp;gt;&amp;#34;
   LINE 1: SELECT * FROM &amp;#34;productos&amp;#34; WHERE &amp;#34;idproducto&amp;#34; = &amp;#39;&amp;lt;img src=x onerror=alert(1)&amp;gt;&amp;#34;
   ```
5. This gets logged via MiniLog and displayed to the user
6. Because of `| raw`, the browser actually executes the JS&lt;/p&gt;
&lt;p&gt;The error logging happens in `Core/Base/D…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: facturascripts/facturascripts&lt;/p&gt;
&lt;p&gt;# Reflected XSS via SQL Error Messages&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A reflected XSS bug has been found in FacturaScripts. The problem is in how error messages get displayed - it&amp;#39;s using Twig&amp;#39;s `| raw` filter which skips HTML escaping. When a database error is triggered (like passing a string where an integer is expected), the error message includes all input and gets rendered without sanitization.&lt;/p&gt;
&lt;p&gt;Attackers can use this to phish credentials from other users since HttpOnly is set on cookies (so stealing cookies directly won&amp;#39;t work, but attackers can inject a fake login form).&lt;/p&gt;
&lt;p&gt;**CVSS 6.1 (Medium-High)**&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## What was Found&lt;/p&gt;
&lt;p&gt;### Where the bug exists in the code:&lt;/p&gt;
&lt;p&gt;`Core/View/Macro/Utils.html.twig`, line 27:&lt;/p&gt;
&lt;p&gt;```twig
{% for item in messages %}
    &amp;lt;div&amp;gt;{{ item.message | raw }}&amp;lt;/div&amp;gt;
{% endfor %}
```&lt;/p&gt;
&lt;p&gt;That `| raw` is the problem. It tells Twig not to escape anything.&lt;/p&gt;
&lt;p&gt;### How it works&lt;/p&gt;
&lt;p&gt;So here&amp;#39;s what happens:&lt;/p&gt;
&lt;p&gt;1. Hhit `/EditProducto?code=&amp;lt;svg onload=alert(1)&amp;gt; or &amp;lt;img src=x onerror=alert(1)&amp;gt;`
2. The app tries to look up a product with that &amp;#34;code&amp;#34;
3. PostgreSQL throws an error because `&amp;lt;svg onload=alert(1)&amp;gt;` isn&amp;#39;t a valid integer
4. The error goes something like:   ```
   ERROR: invalid input syntax for type integer: &amp;#34;&amp;lt;svg onload=alert(1)&amp;gt;&amp;#34;
   LINE 1: SELECT * FROM &amp;#34;productos&amp;#34; WHERE &amp;#34;idproducto&amp;#34; = &amp;#39;&amp;lt;img src=x onerror=alert(1)&amp;gt;&amp;#34;
   ```
5. This gets logged via MiniLog and displayed to the user
6. Because of `| raw`, the browser actually executes the JS&lt;/p&gt;
&lt;p&gt;The error logging happens in `Core/Base/D…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g6w2-q45f-xrp4</guid>
    </item>
  </channel>
</rss>
