<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:03:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275544</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275544</link>
      <description>EUVD-2026-275544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275544</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31822</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31822</link>
      <description>&lt;p&gt;Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt fails, AuthenticationFailureHandler returns a JSON response whose message field is rendered into the DOM using innerHTML, allowing any HTML or JavaScript in that value to be parsed and executed by the browser. The issue is fixed in versions: 2.0.16, 2.1.12, 2.2.3 and above.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt fails, AuthenticationFailureHandler returns a JSON response whose message field is rendered into the DOM using innerHTML, allowing any HTML or JavaScript in that value to be parsed and executed by the browser. The issue is fixed in versions: 2.0.16, 2.1.12, 2.2.3 and above.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31822</guid>
    </item>
    <item>
      <title>GHSA-vgh8-c6fp-7gcg — Sylius has a XSS vulnerability in checkout login form</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vgh8-c6fp-7gcg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: sylius/sylius&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller.&lt;/p&gt;
&lt;p&gt;When a login attempt fails, AuthenticationFailureHandler returns a JSON response whose message field is rendered into the DOM using innerHTML, allowing any HTML or JavaScript in that value to be parsed and executed by the browser.&lt;/p&gt;
&lt;p&gt;The message value originates from `AuthenticationException::getMessageKey()` passed through Symfony&amp;#39;s translator (security domain, using the request locale). In the default Sylius installation, this returns a hardcoded translation key (e.g. &amp;#34;Invalid credentials.&amp;#34;), which is not directly user-controlled. However, using innerHTML with server-derived data violates defense-in-depth principles, and the risk escalates significantly under realistic scenarios:
  - Customized authentication handlers — if a project overrides AuthenticationFailureHandler to include user-supplied data in the message (e.g. &amp;#34;No account found for &amp;lt;username&amp;gt;&amp;#34;), an attacker can inject arbitrary JavaScript directly via the login
  form without any privileged access.
  - Translation injection — if translation files are sourced from an untrusted database or CMS and contain HTML, the message could carry a malicious payload.
  - Man-in-the-Middle — if the response is intercepted (e.g. on HTTP or via a compromised proxy), an attac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: sylius/sylius&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller.&lt;/p&gt;
&lt;p&gt;When a login attempt fails, AuthenticationFailureHandler returns a JSON response whose message field is rendered into the DOM using innerHTML, allowing any HTML or JavaScript in that value to be parsed and executed by the browser.&lt;/p&gt;
&lt;p&gt;The message value originates from `AuthenticationException::getMessageKey()` passed through Symfony&amp;#39;s translator (security domain, using the request locale). In the default Sylius installation, this returns a hardcoded translation key (e.g. &amp;#34;Invalid credentials.&amp;#34;), which is not directly user-controlled. However, using innerHTML with server-derived data violates defense-in-depth principles, and the risk escalates significantly under realistic scenarios:
  - Customized authentication handlers — if a project overrides AuthenticationFailureHandler to include user-supplied data in the message (e.g. &amp;#34;No account found for &amp;lt;username&amp;gt;&amp;#34;), an attacker can inject arbitrary JavaScript directly via the login
  form without any privileged access.
  - Translation injection — if translation files are sourced from an untrusted database or CMS and contain HTML, the message could carry a malicious payload.
  - Man-in-the-Middle — if the response is intercepted (e.g. on HTTP or via a compromised proxy), an attac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vgh8-c6fp-7gcg</guid>
    </item>
  </channel>
</rss>
