<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:20:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275715</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275715</link>
      <description>EUVD-2026-275715</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275715</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31859</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31859</link>
      <description>&lt;p&gt;Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like javascript:alert(document.cookie) contain no HTML tags and pass through strip_tags() completely unmodified, enabling reflected XSS when the return URL is rendered in an href attribute. This vulnerability is fixed in  5.9.7 and 4.17.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like javascript:alert(document.cookie) contain no HTML tags and pass through strip_tags() completely unmodified, enabling reflected XSS when the return URL is rendered in an href attribute. This vulnerability is fixed in  5.9.7 and 4.17.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31859</guid>
    </item>
    <item>
      <title>GHSA-fvwq-45qv-xvhv — CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fvwq-45qv-xvhv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The fix for CVE-2025-35939 in `craftcms/cms` introduced a `strip_tags()` call in `src/web/User.php` to sanitize return URLs before they are stored in the session. However, `strip_tags()` only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like `javascript:alert(document.cookie)` contain no HTML tags and pass through `strip_tags()` completely unmodified, enabling reflected XSS when the return URL is rendered in an `href` attribute.&lt;/p&gt;
&lt;p&gt;### Details
The patched code in is:&lt;/p&gt;
&lt;p&gt;```php
public function setReturnUrl($url): void
{
    parent::setReturnUrl(strip_tags($url));
}
```&lt;/p&gt;
&lt;p&gt;`strip_tags()` removes HTML tags (e.g., `&amp;lt;script&amp;gt;`, `&amp;lt;img&amp;gt;`) from a string, but it is **not** a URL sanitizer. When the sanitized return URL is subsequently rendered in an `href` attribute context (e.g., `&amp;lt;a href=&amp;#34;{{ returnUrl }}&amp;#34;&amp;gt;`), the following dangerous payloads survive `strip_tags()` completely unmodified:&lt;/p&gt;
&lt;p&gt;1. **`javascript:` protocol URLs** -- `javascript:alert(document.cookie)` contains no HTML tags, so `strip_tags()` returns it verbatim. When placed in an `href`, clicking the link executes the JavaScript.&lt;/p&gt;
&lt;p&gt;2. **`data:` URIs** -- `data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==` uses Base64 encoding and contains no tags at all, bypassing `strip_tags()` entirely.&lt;/p&gt;
&lt;p&gt;3. **Protocol-relative URLs** -- `//evil.com/steal` contains no tags and is passed through unchanged. When rendered as an `href`, the browser resolves it relative to the current…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The fix for CVE-2025-35939 in `craftcms/cms` introduced a `strip_tags()` call in `src/web/User.php` to sanitize return URLs before they are stored in the session. However, `strip_tags()` only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like `javascript:alert(document.cookie)` contain no HTML tags and pass through `strip_tags()` completely unmodified, enabling reflected XSS when the return URL is rendered in an `href` attribute.&lt;/p&gt;
&lt;p&gt;### Details
The patched code in is:&lt;/p&gt;
&lt;p&gt;```php
public function setReturnUrl($url): void
{
    parent::setReturnUrl(strip_tags($url));
}
```&lt;/p&gt;
&lt;p&gt;`strip_tags()` removes HTML tags (e.g., `&amp;lt;script&amp;gt;`, `&amp;lt;img&amp;gt;`) from a string, but it is **not** a URL sanitizer. When the sanitized return URL is subsequently rendered in an `href` attribute context (e.g., `&amp;lt;a href=&amp;#34;{{ returnUrl }}&amp;#34;&amp;gt;`), the following dangerous payloads survive `strip_tags()` completely unmodified:&lt;/p&gt;
&lt;p&gt;1. **`javascript:` protocol URLs** -- `javascript:alert(document.cookie)` contains no HTML tags, so `strip_tags()` returns it verbatim. When placed in an `href`, clicking the link executes the JavaScript.&lt;/p&gt;
&lt;p&gt;2. **`data:` URIs** -- `data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==` uses Base64 encoding and contains no tags at all, bypassing `strip_tags()` entirely.&lt;/p&gt;
&lt;p&gt;3. **Protocol-relative URLs** -- `//evil.com/steal` contains no tags and is passed through unchanged. When rendered as an `href`, the browser resolves it relative to the current…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fvwq-45qv-xvhv</guid>
    </item>
  </channel>
</rss>
