<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:38:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-365282</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365282</link>
      <description>EUVD-2026-365282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365282</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52773</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52773</link>
      <description>&lt;p&gt;YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki&amp;#39;s archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still load that archived revision, and execute arbitrary JavaScript in the victim&amp;#39;s browser. The vulnerable form is only rendered when the victim can both read and edit the target page. In restricted deployments this requires a victim with read and write access to that page. On a default doryphore 4.6.5 install, public pages such as PagePrincipale were editable anonymously during validation, so the issue can also affect unauthenticated visitors in that configuration. This issue has been patched in version 4.6.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki&amp;#39;s archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still load that archived revision, and execute arbitrary JavaScript in the victim&amp;#39;s browser. The vulnerable form is only rendered when the victim can both read and edit the target page. In restricted deployments this requires a victim with read and write access to that page. On a default doryphore 4.6.5 install, public pages such as PagePrincipale were editable anonymously during validation, so the issue can also affect unauthenticated visitors in that configuration. This issue has been patched in version 4.6.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52773</guid>
    </item>
    <item>
      <title>GHSA-35f3-pg38-486f — YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-35f3-pg38-486f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yeswiki/yeswiki&lt;/p&gt;
&lt;p&gt;### Summary
YesWiki&amp;#39;s archived-revision view reflects the `time` `GET` parameter into a hidden HTML input in `handlers/page/show.php` without escaping. Because MySQL coerces malformed `DATETIME` strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still load that archived revision, and execute arbitrary JavaScript in the victim&amp;#39;s browser.&lt;/p&gt;
&lt;p&gt;The vulnerable form is only rendered when the victim can both read and edit the target page. In restricted deployments this requires a victim with `read` and `write` access to that page. On a default `doryphore 4.6.5` install, public pages such as `PagePrincipale` were editable anonymously during validation, so the issue can also affect unauthenticated visitors in that configuration.&lt;/p&gt;
&lt;p&gt;### Details
The request routing path uses the user-controlled `time` parameter to load a specific page revision. In `includes/YesWiki.php` around `Run()` line `1223`, the request is routed through:&lt;/p&gt;
&lt;p&gt;```php
$this-&amp;gt;SetPage($this-&amp;gt;LoadPage($tag, isset($_REQUEST[&amp;#39;time&amp;#39;]) ? $_REQUEST[&amp;#39;time&amp;#39;] : &amp;#39;&amp;#39;));
```&lt;/p&gt;
&lt;p&gt;`LoadPage()` delegates to `PageManager::getOne()` in `includes/services/PageManager.php` around line `75`, which builds a SQL predicate directly from the supplied revision time:&lt;/p&gt;
&lt;p&gt;```php
$timeQuery = $time ? &amp;#34;time = &amp;#39;{$this-&amp;gt;dbService-&amp;gt;escape($time)}&amp;#39;&amp;#34; : &amp;#34;latest = &amp;#39;Y&amp;#39;&amp;#34;;
```&lt;/p&gt;
&lt;p&gt;If the loaded page is an archived revision (`latest == &amp;#39;N&amp;#39;`) and the current user has `write` access, `handlers/page/show.php` around lines `43-49` renders…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: yeswiki/yeswiki&lt;/p&gt;
&lt;p&gt;### Summary
YesWiki&amp;#39;s archived-revision view reflects the `time` `GET` parameter into a hidden HTML input in `handlers/page/show.php` without escaping. Because MySQL coerces malformed `DATETIME` strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still load that archived revision, and execute arbitrary JavaScript in the victim&amp;#39;s browser.&lt;/p&gt;
&lt;p&gt;The vulnerable form is only rendered when the victim can both read and edit the target page. In restricted deployments this requires a victim with `read` and `write` access to that page. On a default `doryphore 4.6.5` install, public pages such as `PagePrincipale` were editable anonymously during validation, so the issue can also affect unauthenticated visitors in that configuration.&lt;/p&gt;
&lt;p&gt;### Details
The request routing path uses the user-controlled `time` parameter to load a specific page revision. In `includes/YesWiki.php` around `Run()` line `1223`, the request is routed through:&lt;/p&gt;
&lt;p&gt;```php
$this-&amp;gt;SetPage($this-&amp;gt;LoadPage($tag, isset($_REQUEST[&amp;#39;time&amp;#39;]) ? $_REQUEST[&amp;#39;time&amp;#39;] : &amp;#39;&amp;#39;));
```&lt;/p&gt;
&lt;p&gt;`LoadPage()` delegates to `PageManager::getOne()` in `includes/services/PageManager.php` around line `75`, which builds a SQL predicate directly from the supplied revision time:&lt;/p&gt;
&lt;p&gt;```php
$timeQuery = $time ? &amp;#34;time = &amp;#39;{$this-&amp;gt;dbService-&amp;gt;escape($time)}&amp;#39;&amp;#34; : &amp;#34;latest = &amp;#39;Y&amp;#39;&amp;#34;;
```&lt;/p&gt;
&lt;p&gt;If the loaded page is an archived revision (`latest == &amp;#39;N&amp;#39;`) and the current user has `write` access, `handlers/page/show.php` around lines `43-49` renders…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-35f3-pg38-486f</guid>
    </item>
  </channel>
</rss>
