<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 14:34:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-374386</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374386</link>
      <description>EUVD-2026-374386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374386</guid>
    </item>
    <item>
      <title>fkie_cve-2026-76089</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76089</link>
      <description>&lt;p&gt;Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie&amp;#39;s formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie&amp;#39;s formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-76089</guid>
    </item>
    <item>
      <title>GHSA-9rg8-2wvr-fgjh — Formie: Missing authorization on sent notification resend modal exposes submission PII</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9rg8-2wvr-fgjh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: verbb/formie&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The control panel action `formie/sent-notifications/get-resend-modal-content` (`SentNotificationsController::actionGetResendModalContent`) performed only `requireAcceptsJson()` and loaded a `SentNotification` by request `id` without permission or object-level authorization checks.&lt;/p&gt;
&lt;p&gt;Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without `formie-accessSentNotifications` or equivalent permission. Sibling actions in the same controller enforced authorization.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in **3.1.31** (Craft 5) and **2.2.23** (Craft 4).&lt;/p&gt;
&lt;p&gt;Craft 5: `canView()` is enforced after loading, consistent with `actionEdit`.  
Craft 4: `formie-viewSentNotifications` permission is required.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Restrict CP access to trusted users only until upgraded. No configuration workaround.&lt;/p&gt;
&lt;p&gt;- Reported by Jorge González (jorge@jmilla.es)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: verbb/formie&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The control panel action `formie/sent-notifications/get-resend-modal-content` (`SentNotificationsController::actionGetResendModalContent`) performed only `requireAcceptsJson()` and loaded a `SentNotification` by request `id` without permission or object-level authorization checks.&lt;/p&gt;
&lt;p&gt;Any authenticated user who could invoke the action could enumerate notification IDs and read full email content — including recipient headers and the complete HTML body containing submitted form data (PII) — without `formie-accessSentNotifications` or equivalent permission. Sibling actions in the same controller enforced authorization.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in **3.1.31** (Craft 5) and **2.2.23** (Craft 4).&lt;/p&gt;
&lt;p&gt;Craft 5: `canView()` is enforced after loading, consistent with `actionEdit`.  
Craft 4: `formie-viewSentNotifications` permission is required.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Restrict CP access to trusted users only until upgraded. No configuration workaround.&lt;/p&gt;
&lt;p&gt;- Reported by Jorge González (jorge@jmilla.es)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9rg8-2wvr-fgjh</guid>
    </item>
  </channel>
</rss>
