<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:46:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-362992</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362992</link>
      <description>EUVD-2026-362992</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362992</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84800</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84800</link>
      <description>&lt;p&gt;Craft CMS versions &amp;gt;= 5.0.0-RC1 and &amp;lt; 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer&amp;#39;s asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft CMS versions &amp;gt;= 5.0.0-RC1 and &amp;lt; 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer&amp;#39;s asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84800</guid>
    </item>
    <item>
      <title>GHSA-gr8m-2p6r-xr29</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gr8m-2p6r-xr29</link>
      <description>&lt;p&gt;Craft CMS versions &amp;gt;= 5.0.0-RC1 and &amp;lt; 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer&amp;#39;s asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft CMS versions &amp;gt;= 5.0.0-RC1 and &amp;lt; 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer&amp;#39;s asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gr8m-2p6r-xr29</guid>
    </item>
  </channel>
</rss>
