<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 15:16:08 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-59332 — 3DAlloy allows stored XSS through attributes provided to the 3d parser tag/function</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-59332</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; dolfinus 3DAlloy&lt;/p&gt;
&lt;p&gt;3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the &amp;lt;3d&amp;gt; parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; dolfinus 3DAlloy&lt;/p&gt;
&lt;p&gt;3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the &amp;lt;3d&amp;gt; parser tag and the {{#3d}} parser function allow users to provide custom attributes that are then appended to the canvas HTML element that is being output by the extension. The attributes are not sanitized, which means that arbitrary JavaScript can be inserted and executed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-59332</guid>
    </item>
  </channel>
</rss>
