<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:01:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322433</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322433</link>
      <description>EUVD-2026-322433</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322433</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46360</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46360</link>
      <description>&lt;p&gt;phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG files with deeply nested ampersand encoding around numeric HTML entities to reconstruct javascript: URLs, which execute arbitrary JavaScript when clicked by other users viewing the uploaded SVG.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG files with deeply nested ampersand encoding around numeric HTML entities to reconstruct javascript: URLs, which execute arbitrary JavaScript when clicked by other users viewing the uploaded SVG.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46360</guid>
    </item>
    <item>
      <title>GHSA-whqh-9pq5-c7r3 — phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-whqh-9pq5-c7r3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpmyfaq/phpmyfaq, Packagist: thorsten/phpmyfaq&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `SvgSanitizer::decodeAllEntities()` method limits recursive entity decoding to 5 iterations. By wrapping each character of `javascript` in an `href` attribute value with 5 levels of `&amp;amp;amp;` encoding around numeric HTML entities (e.g., `&amp;amp;amp;amp;amp;amp;amp;#106;` for `j`), an attacker can bypass both `isSafe()` detection and `sanitize()` removal. The uploaded SVG is served from the application origin with `image/svg+xml` content type, and the browser&amp;#39;s XML parser fully decodes the remaining `&amp;amp;#NNN;` entities, resulting in a clickable `javascript:` link that executes arbitrary JavaScript.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**Root cause:** `decodeAllEntities()` at `phpmyfaq/src/phpMyFAQ/Helper/SvgSanitizer.php:223-249` limits entity decoding to `maxIterations=5`. Each iteration: (1) decodes `&amp;amp;#NNN;` numeric entities, (2) decodes `&amp;amp;#xHH;` hex entities, (3) calls `html_entity_decode()` which resolves one level of `&amp;amp;amp;` → `&amp;amp;`. With 5 levels of `&amp;amp;amp;` wrapping, all 5 iterations are consumed unwinding the `&amp;amp;amp;` nesting, leaving the final `&amp;amp;#NNN;` numeric entities unresolved.&lt;/p&gt;
&lt;p&gt;**Code path:**&lt;/p&gt;
&lt;p&gt;1. Authenticated user with `FAQ_EDIT` permission uploads SVG via `POST /admin/api/content/images` (`ImageController::upload()` at line 39)
2. File extension is `svg` → `SvgSanitizer::isSafe()` called (line 114)
3. `isSafe()` calls `decodeAllEntities()` — 5 iterations resolve `&amp;amp;amp;` nesting but leave `&amp;amp;#106;&amp;amp;#97;...` (numeric entities for `javascript`)
4. Pattern matching at line 47 (`/href\s*=\…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpmyfaq/phpmyfaq, Packagist: thorsten/phpmyfaq&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `SvgSanitizer::decodeAllEntities()` method limits recursive entity decoding to 5 iterations. By wrapping each character of `javascript` in an `href` attribute value with 5 levels of `&amp;amp;amp;` encoding around numeric HTML entities (e.g., `&amp;amp;amp;amp;amp;amp;amp;#106;` for `j`), an attacker can bypass both `isSafe()` detection and `sanitize()` removal. The uploaded SVG is served from the application origin with `image/svg+xml` content type, and the browser&amp;#39;s XML parser fully decodes the remaining `&amp;amp;#NNN;` entities, resulting in a clickable `javascript:` link that executes arbitrary JavaScript.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**Root cause:** `decodeAllEntities()` at `phpmyfaq/src/phpMyFAQ/Helper/SvgSanitizer.php:223-249` limits entity decoding to `maxIterations=5`. Each iteration: (1) decodes `&amp;amp;#NNN;` numeric entities, (2) decodes `&amp;amp;#xHH;` hex entities, (3) calls `html_entity_decode()` which resolves one level of `&amp;amp;amp;` → `&amp;amp;`. With 5 levels of `&amp;amp;amp;` wrapping, all 5 iterations are consumed unwinding the `&amp;amp;amp;` nesting, leaving the final `&amp;amp;#NNN;` numeric entities unresolved.&lt;/p&gt;
&lt;p&gt;**Code path:**&lt;/p&gt;
&lt;p&gt;1. Authenticated user with `FAQ_EDIT` permission uploads SVG via `POST /admin/api/content/images` (`ImageController::upload()` at line 39)
2. File extension is `svg` → `SvgSanitizer::isSafe()` called (line 114)
3. `isSafe()` calls `decodeAllEntities()` — 5 iterations resolve `&amp;amp;amp;` nesting but leave `&amp;amp;#106;&amp;amp;#97;...` (numeric entities for `javascript`)
4. Pattern matching at line 47 (`/href\s*=\…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-whqh-9pq5-c7r3</guid>
    </item>
  </channel>
</rss>
