<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from nvd</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:44:07 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-94422 — xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-94422</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; xdg-dbus-proxy, Fedora, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10&lt;/p&gt;
&lt;p&gt;An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; xdg-dbus-proxy, Fedora, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10&lt;/p&gt;
&lt;p&gt;An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-94422</guid>
      <pubDate>Fri, 02 Oct 2026 13:54:10 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-93875 — JetAppointment &lt;= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-93875</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Crocoblock JetAppointment&lt;/p&gt;
&lt;p&gt;The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;friendlyTime&amp;#39; parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator&amp;#39;s browser when the appointment details popup is opened in the WordPress admin panel.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Crocoblock JetAppointment&lt;/p&gt;
&lt;p&gt;The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;friendlyTime&amp;#39; parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator&amp;#39;s browser when the appointment details popup is opened in the WordPress admin panel.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-93875</guid>
      <pubDate>Fri, 02 Oct 2026 13:29:05 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-85215 — SQL Injection in GG Soft's Paperwork</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-85215</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GG Soft Software Services Inc. Paperwork&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements used in an SQL command (&amp;#39;SQL injection&amp;#39;) vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection.&lt;/p&gt;
&lt;p&gt;This issue affects Paperwork: through 2026-09-09.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GG Soft Software Services Inc. Paperwork&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements used in an SQL command (&amp;#39;SQL injection&amp;#39;) vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection.&lt;/p&gt;
&lt;p&gt;This issue affects Paperwork: through 2026-09-09.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-85215</guid>
      <pubDate>Fri, 02 Oct 2026 13:01:52 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-19652 — Divi Membership &lt;= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-19652</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; DiviEngine Divi Membership&lt;/p&gt;
&lt;p&gt;The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user&amp;#39;s role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; DiviEngine Divi Membership&lt;/p&gt;
&lt;p&gt;The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user&amp;#39;s role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-19652</guid>
      <pubDate>Fri, 02 Oct 2026 13:29:05 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104721 — Logback: Incomplete protection against CVE-2026-19880</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-104721</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; QOS.CH Sarl Logback-classic&lt;/p&gt;
&lt;p&gt;Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an 
MDC-based discriminator value flows unsanitized into a nested 
FileAppender path, letting an attacker who influences that MDC value 
(e.g. via an HTTP header)
 create and append log files outside the intended directory.&lt;/p&gt;
&lt;p&gt;This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; QOS.CH Sarl Logback-classic&lt;/p&gt;
&lt;p&gt;Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an 
MDC-based discriminator value flows unsanitized into a nested 
FileAppender path, letting an attacker who influences that MDC value 
(e.g. via an HTTP header)
 create and append log files outside the intended directory.&lt;/p&gt;
&lt;p&gt;This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-104721</guid>
      <pubDate>Fri, 02 Oct 2026 13:21:59 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104614 — CodeAstro Simple Pharmacy Management System delete.php sql injection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-104614</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CodeAstro Simple Pharmacy Management System&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CodeAstro Simple Pharmacy Management System&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-104614</guid>
      <pubDate>Fri, 02 Oct 2026 14:00:09 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104613 — CodeAstro Simple Pharmacy Management System view.php sql injection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-104613</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CodeAstro Simple Pharmacy Management System&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CodeAstro Simple Pharmacy Management System&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-104613</guid>
      <pubDate>Fri, 02 Oct 2026 13:15:07 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-96289 — Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-96289</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Thrift&lt;/p&gt;
&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Thrift&lt;/p&gt;
&lt;p&gt;Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-96289</guid>
      <pubDate>Fri, 02 Oct 2026 12:07:02 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-96287 — Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadrati…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-96287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Thrift&lt;/p&gt;
&lt;p&gt;Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Thrift&lt;/p&gt;
&lt;p&gt;Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-96287</guid>
      <pubDate>Fri, 02 Oct 2026 12:05:59 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-96286 — Apache Thrift: Perl servers end `serve()` when serving one connection fails</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-96286</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Thrift&lt;/p&gt;
&lt;p&gt;Uncaught exception vulnerability in Apache Thrift Perl bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Thrift&lt;/p&gt;
&lt;p&gt;Uncaught exception vulnerability in Apache Thrift Perl bindings.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Thrift: before 0.25.0.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 0.25.0, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-96286</guid>
      <pubDate>Fri, 02 Oct 2026 12:04:28 +0000</pubDate>
    </item>
  </channel>
</rss>
