<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 00:31:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-349339</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349339</link>
      <description>EUVD-2026-349339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349339</guid>
    </item>
    <item>
      <title>fkie_cve-2026-64662</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64662</link>
      <description>&lt;p&gt;Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-64662</guid>
    </item>
    <item>
      <title>GHSA-qh8c-7588-qfrv — Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qh8c-7588-qfrv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: statamic/cms&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An authenticated Control Panel user could view content from entries they don&amp;#39;t have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been fixed in 5.74.1 and 6.24.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: statamic/cms&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An authenticated Control Panel user could view content from entries they don&amp;#39;t have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been fixed in 5.74.1 and 6.24.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qh8c-7588-qfrv</guid>
    </item>
  </channel>
</rss>
