<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:42:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-358421</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358421</link>
      <description>EUVD-2026-358421</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358421</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61807</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61807</link>
      <description>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selector, concatenates countId.substring(1) into an HTML string, and passes the string to jQuery .after(). A crafted name can therefore execute JavaScript when an authenticated user views the manufacturer detail page or supplier detail page, potentially exposing data or actions available to that session. This issue is fixed in version 8.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selector, concatenates countId.substring(1) into an HTML string, and passes the string to jQuery .after(). A crafted name can therefore execute JavaScript when an authenticated user views the manufacturer detail page or supplier detail page, potentially exposing data or actions available to that session. This issue is fixed in version 8.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61807</guid>
    </item>
    <item>
      <title>GHSA-c8qc-wf67-342w — Snipe-IT: Stored DOM XSS via table selected-count IDs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c8qc-wf67-342w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;### Impact
The table component derives data-selected-count-id from the component $name value. On manufacturer and supplier detail pages, stored manufacturer or supplier names are passed into affected table components as that name value. The client-side JavaScript later reads the browser-decoded data-selected-count-id, uses it as a selector, and concatenates countId.substring(1) directly into an HTML string passed to jQuery .after().&lt;/p&gt;
&lt;p&gt;Affected commit:&lt;/p&gt;
&lt;p&gt;`b224cc636c6780386e3f73f03d1171f52ab4c37a`&lt;/p&gt;
&lt;p&gt;Example payload for a manufacturer or supplier name:
`x[foo=&amp;#34;&amp;gt;&amp;lt;svg/onload=alert(1)&amp;gt;&amp;#34;]&amp;gt;`&lt;/p&gt;
&lt;p&gt;The issue appears to involve the following flow:&lt;/p&gt;
&lt;p&gt;Stored supplier/manufacturer name
-&amp;gt; table component data-selected-count-id
-&amp;gt; browser decodes the attribute
-&amp;gt; JavaScript reads countId
-&amp;gt; countId is used as a selector
-&amp;gt; countId.substring(1) is concatenated into HTML
-&amp;gt; jQuery .after() inserts attacker-controlled markup
-&amp;gt; JavaScript executes in the victim&amp;#39;s browser&lt;/p&gt;
&lt;p&gt;Potential impact includes arbitrary JavaScript execution in the browser of an authenticated Snipe-IT user who views the affected supplier or manufacturer detail page. If the victim has elevated privileges, this may allow access to data or actions available to that user&amp;#39;s session.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;### Impact
The table component derives data-selected-count-id from the component $name value. On manufacturer and supplier detail pages, stored manufacturer or supplier names are passed into affected table components as that name value. The client-side JavaScript later reads the browser-decoded data-selected-count-id, uses it as a selector, and concatenates countId.substring(1) directly into an HTML string passed to jQuery .after().&lt;/p&gt;
&lt;p&gt;Affected commit:&lt;/p&gt;
&lt;p&gt;`b224cc636c6780386e3f73f03d1171f52ab4c37a`&lt;/p&gt;
&lt;p&gt;Example payload for a manufacturer or supplier name:
`x[foo=&amp;#34;&amp;gt;&amp;lt;svg/onload=alert(1)&amp;gt;&amp;#34;]&amp;gt;`&lt;/p&gt;
&lt;p&gt;The issue appears to involve the following flow:&lt;/p&gt;
&lt;p&gt;Stored supplier/manufacturer name
-&amp;gt; table component data-selected-count-id
-&amp;gt; browser decodes the attribute
-&amp;gt; JavaScript reads countId
-&amp;gt; countId is used as a selector
-&amp;gt; countId.substring(1) is concatenated into HTML
-&amp;gt; jQuery .after() inserts attacker-controlled markup
-&amp;gt; JavaScript executes in the victim&amp;#39;s browser&lt;/p&gt;
&lt;p&gt;Potential impact includes arbitrary JavaScript execution in the browser of an authenticated Snipe-IT user who views the affected supplier or manufacturer detail page. If the victim has elevated privileges, this may allow access to data or actions available to that user&amp;#39;s session.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c8qc-wf67-342w</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2073 — Snipe-IT: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073</guid>
    </item>
  </channel>
</rss>
