<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:04:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292451</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292451</link>
      <description>EUVD-2026-292451</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292451</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40926</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40926</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check (`Category::canCreateCategory()` / `User::isAdmin()`) and perform state-changing actions against the database without calling `isGlobalTokenValid()` or `forbidIfIsUntrustedRequest()`. Peer endpoints in the same directory (`pluginSwitch.json.php`, `pluginRunDatabaseScript.json.php`) do enforce the CSRF token, so the missing checks are an omission rather than a design choice. An attacker who lures a logged-in admin to a malicious page can create, update, or delete categories and force execution of any installed plugin&amp;#39;s `updateScript()` method in the admin&amp;#39;s session. Commit ee5615153c40628ab3ec6fe04962d1f92e67d3e2 contains a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check (`Category::canCreateCategory()` / `User::isAdmin()`) and perform state-changing actions against the database without calling `isGlobalTokenValid()` or `forbidIfIsUntrustedRequest()`. Peer endpoints in the same directory (`pluginSwitch.json.php`, `pluginRunDatabaseScript.json.php`) do enforce the CSRF token, so the missing checks are an omission rather than a design choice. An attacker who lures a logged-in admin to a malicious page can create, update, or delete categories and force execution of any installed plugin&amp;#39;s `updateScript()` method in the admin&amp;#39;s session. Commit ee5615153c40628ab3ec6fe04962d1f92e67d3e2 contains a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40926</guid>
    </item>
    <item>
      <title>GHSA-ffw8-fwxp-h64w — WWBN AVideo has Multiple CSRF Vulnerabilities in Admin JSON Endpoints (Category CRUD, Plugin Update Script)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ffw8-fwxp-h64w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check (`Category::canCreateCategory()` / `User::isAdmin()`) and perform state-changing actions against the database without calling `isGlobalTokenValid()` or `forbidIfIsUntrustedRequest()`. Peer endpoints in the same directory (`pluginSwitch.json.php`, `pluginRunDatabaseScript.json.php`) do enforce the CSRF token, so the missing checks are an omission rather than a design choice. An attacker who lures a logged-in admin to a malicious page can create, update, or delete categories and force execution of any installed plugin&amp;#39;s `updateScript()` method in the admin&amp;#39;s session.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;AVideo&amp;#39;s CSRF defense is not applied globally — each endpoint must explicitly call `isGlobalTokenValid()` (defined in `objects/functions.php:2313`), which verifies `$_REQUEST[&amp;#39;globalToken&amp;#39;]`. A search across the codebase shows 18 files that correctly invoke `forbidIfIsUntrustedRequest()` or `isGlobalTokenValid()`, while the three endpoints below do not.&lt;/p&gt;
&lt;p&gt;### 1. `objects/categoryAddNew.json.php:18` — CSRF create/overwrite category&lt;/p&gt;
&lt;p&gt;```php
 18 if (!Category::canCreateCategory()) {
 19     $obj-&amp;gt;msg = __(&amp;#34;Permission denied&amp;#34;);
 20     die(json_encode($obj));
 21 }
 22
 23 $objCat = new Category(intval(@$_POST[&amp;#39;id&amp;#39;]));
 24 $objCat-&amp;gt;setName($_POST[&amp;#39;name&amp;#39;]);
 25 $objCat-&amp;gt;setClean_name($_POST[&amp;#39;clean_name&amp;#39;]);
 26 $objCat-&amp;gt;se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check (`Category::canCreateCategory()` / `User::isAdmin()`) and perform state-changing actions against the database without calling `isGlobalTokenValid()` or `forbidIfIsUntrustedRequest()`. Peer endpoints in the same directory (`pluginSwitch.json.php`, `pluginRunDatabaseScript.json.php`) do enforce the CSRF token, so the missing checks are an omission rather than a design choice. An attacker who lures a logged-in admin to a malicious page can create, update, or delete categories and force execution of any installed plugin&amp;#39;s `updateScript()` method in the admin&amp;#39;s session.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;AVideo&amp;#39;s CSRF defense is not applied globally — each endpoint must explicitly call `isGlobalTokenValid()` (defined in `objects/functions.php:2313`), which verifies `$_REQUEST[&amp;#39;globalToken&amp;#39;]`. A search across the codebase shows 18 files that correctly invoke `forbidIfIsUntrustedRequest()` or `isGlobalTokenValid()`, while the three endpoints below do not.&lt;/p&gt;
&lt;p&gt;### 1. `objects/categoryAddNew.json.php:18` — CSRF create/overwrite category&lt;/p&gt;
&lt;p&gt;```php
 18 if (!Category::canCreateCategory()) {
 19     $obj-&amp;gt;msg = __(&amp;#34;Permission denied&amp;#34;);
 20     die(json_encode($obj));
 21 }
 22
 23 $objCat = new Category(intval(@$_POST[&amp;#39;id&amp;#39;]));
 24 $objCat-&amp;gt;setName($_POST[&amp;#39;name&amp;#39;]);
 25 $objCat-&amp;gt;setClean_name($_POST[&amp;#39;clean_name&amp;#39;]);
 26 $objCat-&amp;gt;se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ffw8-fwxp-h64w</guid>
    </item>
  </channel>
</rss>
