<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from nvd</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:45:14 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-50356 — Press has a potential 2FA bypass</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-50356</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; frappe press&lt;/p&gt;
&lt;p&gt;Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn&amp;#39;t be able to login by bypassing the 2FA. Only users who have enabled 2FA are affected. Commit ba0007c28ac814260f836849bc07d29beea7deb6 patches this bug.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; frappe press&lt;/p&gt;
&lt;p&gt;Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn&amp;#39;t be able to login by bypassing the 2FA. Only users who have enabled 2FA are affected. Commit ba0007c28ac814260f836849bc07d29beea7deb6 patches this bug.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-50356</guid>
      <pubDate>Thu, 31 Oct 2024 18:02:42 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-11173 — Reauth for enabling 2FA can be bypassed by submitting a form</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-11173</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation OATHAuth&lt;/p&gt;
&lt;p&gt;Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php.&lt;/p&gt;
&lt;p&gt;This issue affects OATHAuth: from * before 1.39.14, 1.43.4, 1.44.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation OATHAuth&lt;/p&gt;
&lt;p&gt;Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php.&lt;/p&gt;
&lt;p&gt;This issue affects OATHAuth: from * before 1.39.14, 1.43.4, 1.44.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-11173</guid>
      <pubDate>Tue, 03 Feb 2026 00:27:45 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-1680</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-1680</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Moxa TN-4500A Series, Moxa TN-5500A Series, Moxa TN-G4500 Series, Moxa TN-G6500 Series&lt;/p&gt;
&lt;p&gt;An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Moxa TN-4500A Series, Moxa TN-5500A Series, Moxa TN-G4500 Series, Moxa TN-G6500 Series&lt;/p&gt;
&lt;p&gt;An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-1680</guid>
      <pubDate>Thu, 23 Oct 2025 13:56:39 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-26862 — PingFederate unexpected browser flow initiation in redirectless mode</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-26862</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ping Identity PingFederate&lt;/p&gt;
&lt;p&gt;Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ping Identity PingFederate&lt;/p&gt;
&lt;p&gt;Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-26862</guid>
      <pubDate>Mon, 27 Oct 2025 14:39:41 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-32696 — "reupload-own" restriction can be bypassed by reverting file</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-32696</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-32696</guid>
      <pubDate>Thu, 10 Apr 2025 18:28:48 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-32697 — Cascading protection is not preventing file reversions</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-32697</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: before 1.42.6, 1.43.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: before 1.42.6, 1.43.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-32697</guid>
      <pubDate>Thu, 10 Apr 2025 18:29:17 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-3469 — i18n XSS vulnerability in HTMLMultiSelectField when sections are used</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-3469</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-3469</guid>
      <pubDate>Thu, 10 Apr 2025 18:28:13 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-49823 — Conda Constructor Command Injection via Unsanitized User Input (Low)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-49823</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; conda constructor&lt;/p&gt;
&lt;p&gt;(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized user input as shell code. Although the script runs with user privileges (not root), an attacker could exploit this by injecting arbitrary commands through a malicious path during installation. Exploitation requires explicit user action. This issue has been patched in version 3.11.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; conda constructor&lt;/p&gt;
&lt;p&gt;(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized user input as shell code. Although the script runs with user privileges (not root), an attacker could exploit this by injecting arbitrary commands through a malicious path during installation. Exploitation requires explicit user action. This issue has been patched in version 3.11.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-49823</guid>
      <pubDate>Tue, 17 Jun 2025 02:21:17 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-61635 — Add rate limiting to ApiFancyCaptchaReload</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-61635</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation ConfirmEdit&lt;/p&gt;
&lt;p&gt;Vulnerability in Wikimedia Foundation ConfirmEdit. This vulnerability is associated with program files includes/FancyCaptcha/ApiFancyCaptchaReload.Php.&lt;/p&gt;
&lt;p&gt;This issue affects ConfirmEdit: *.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation ConfirmEdit&lt;/p&gt;
&lt;p&gt;Vulnerability in Wikimedia Foundation ConfirmEdit. This vulnerability is associated with program files includes/FancyCaptcha/ApiFancyCaptchaReload.Php.&lt;/p&gt;
&lt;p&gt;This issue affects ConfirmEdit: *.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-61635</guid>
      <pubDate>Mon, 02 Feb 2026 23:26:14 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2025-61644 — i18n XSS through Special:Watchlist</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-61644</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/WatchlistTopSectionWidget.Js.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: from * before &amp;gt; fb856ce9cf121e046305116852cca4899ecb48ca.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Wikimedia Foundation MediaWiki&lt;/p&gt;
&lt;p&gt;Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Rcfilters/ui/WatchlistTopSectionWidget.Js.&lt;/p&gt;
&lt;p&gt;This issue affects MediaWiki: from * before &amp;gt; fb856ce9cf121e046305116852cca4899ecb48ca.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-61644</guid>
      <pubDate>Mon, 02 Feb 2026 23:57:17 +0000</pubDate>
    </item>
  </channel>
</rss>
