<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:45:57 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-50644 — SQL Injection in SOPlanning Audit Retention Configuration</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-50644</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SOPlanning&lt;/p&gt;
&lt;p&gt;SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user).&lt;/p&gt;
&lt;p&gt;This issue was fixed in version 1.56.01.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SOPlanning&lt;/p&gt;
&lt;p&gt;SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user).&lt;/p&gt;
&lt;p&gt;This issue was fixed in version 1.56.01.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-50644</guid>
    </item>
  </channel>
</rss>
