<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 10:41:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328860</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328860</link>
      <description>EUVD-2026-328860</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328860</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56393</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56393</link>
      <description>&lt;p&gt;Craft CMS 4.x (&amp;gt;= 4.0.0-RC1, &amp;lt; 4.17.0-beta.1) and 5.x (&amp;gt;= 5.0.0-RC1, &amp;lt; 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious payloads into section names, volume names, user group names, global set names, generated field names, checkbox/radio option labels, and custom source labels, causing arbitrary JavaScript to execute in other users&amp;#39; control-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft CMS 4.x (&amp;gt;= 4.0.0-RC1, &amp;lt; 4.17.0-beta.1) and 5.x (&amp;gt;= 5.0.0-RC1, &amp;lt; 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious payloads into section names, volume names, user group names, global set names, generated field names, checkbox/radio option labels, and custom source labels, causing arbitrary JavaScript to execute in other users&amp;#39; control-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56393</guid>
    </item>
    <item>
      <title>GHSA-4mgv-366x-qxvx — Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4mgv-366x-qxvx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;## Overview of all XSS Reports&lt;/p&gt;
&lt;p&gt;Multiple stored XSS vulnerabilities were found in Craft CMS. They were split into **4 reports** as follows:&lt;/p&gt;
&lt;p&gt;| Report | What&amp;#39;s Vulnerable | Why Separate |
|--------|-------------------|--------------|
| **This Report (1)** | Multiple settings names | Twig Template: `_includes/forms/checkbox.twig` |
| **Report 2** | Entry Types Name | Twig Template: `_includes/forms/editableTable.twig` |
| **Report 3** | Card Attributes in Field Layout | `helpers/Cp.php` |
| **Report 4 (Commerce)** | Product Type Name | Source in Commerce, sink in CMS - will report this one via Commerce GHSA |&lt;/p&gt;
&lt;p&gt;Reports 2, 3, and 4 are clearly distinct locations. For this report (Report 1), it was not clear whether to split or consolidate these 7 bugs. The bug report was consolidated and the final categorization should be left to the judgement of the user.&lt;/p&gt;
&lt;p&gt;**Note:** This overview is only in this Report. Other reports only reference this one.&lt;/p&gt;
&lt;p&gt;---
## Summary&lt;/p&gt;
&lt;p&gt;Stored XSS in multiple settings. Names/labels are rendered without sanitization via `checkbox.twig` template which uses `{{ label|raw }}`.&lt;/p&gt;
&lt;p&gt;---
## Affected Sources&lt;/p&gt;
&lt;p&gt;| #   | Source (injection point)                                                 | Sink (where payload reflects)                 |
| --- | ------------------------------------------------------------------------ | --------------------------------------------- |
| 1   | Section Name (`/admin/settings/sections`)                                | Entries field -&amp;gt; So…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;## Overview of all XSS Reports&lt;/p&gt;
&lt;p&gt;Multiple stored XSS vulnerabilities were found in Craft CMS. They were split into **4 reports** as follows:&lt;/p&gt;
&lt;p&gt;| Report | What&amp;#39;s Vulnerable | Why Separate |
|--------|-------------------|--------------|
| **This Report (1)** | Multiple settings names | Twig Template: `_includes/forms/checkbox.twig` |
| **Report 2** | Entry Types Name | Twig Template: `_includes/forms/editableTable.twig` |
| **Report 3** | Card Attributes in Field Layout | `helpers/Cp.php` |
| **Report 4 (Commerce)** | Product Type Name | Source in Commerce, sink in CMS - will report this one via Commerce GHSA |&lt;/p&gt;
&lt;p&gt;Reports 2, 3, and 4 are clearly distinct locations. For this report (Report 1), it was not clear whether to split or consolidate these 7 bugs. The bug report was consolidated and the final categorization should be left to the judgement of the user.&lt;/p&gt;
&lt;p&gt;**Note:** This overview is only in this Report. Other reports only reference this one.&lt;/p&gt;
&lt;p&gt;---
## Summary&lt;/p&gt;
&lt;p&gt;Stored XSS in multiple settings. Names/labels are rendered without sanitization via `checkbox.twig` template which uses `{{ label|raw }}`.&lt;/p&gt;
&lt;p&gt;---
## Affected Sources&lt;/p&gt;
&lt;p&gt;| #   | Source (injection point)                                                 | Sink (where payload reflects)                 |
| --- | ------------------------------------------------------------------------ | --------------------------------------------- |
| 1   | Section Name (`/admin/settings/sections`)                                | Entries field -&amp;gt; So…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4mgv-366x-qxvx</guid>
    </item>
  </channel>
</rss>
