<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:22:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-269941</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-269941</link>
      <description>EUVD-2026-269941</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-269941</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26746</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26746</link>
      <description>&lt;p&gt;OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26746</guid>
    </item>
    <item>
      <title>GHSA-8p85-wjp4-3w4m</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8p85-wjp4-3w4m</link>
      <description>&lt;p&gt;OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8p85-wjp4-3w4m</guid>
    </item>
  </channel>
</rss>
