<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_ubuntu</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:05:38 +0000</lastBuildDate>
    <item>
      <title>UBUNTU-CVE-2026-103048</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-103048</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mediawiki, Ubuntu:Pro:20.04:LTS: mediawiki, Ubuntu:Pro:22.04:LTS: mediawiki, Ubuntu:Pro:24.04:LTS: mediawiki, Ubuntu:26.04:LTS: mediawiki&lt;/p&gt;
&lt;p&gt;URL redirection to untrusted site (&amp;#39;open redirect&amp;#39;) vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mediawiki, Ubuntu:Pro:20.04:LTS: mediawiki, Ubuntu:Pro:22.04:LTS: mediawiki, Ubuntu:Pro:24.04:LTS: mediawiki, Ubuntu:26.04:LTS: mediawiki&lt;/p&gt;
&lt;p&gt;URL redirection to untrusted site (&amp;#39;open redirect&amp;#39;) vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-103048</guid>
      <pubDate>Wed, 30 Sep 2026 00:16:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-103044</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-103044</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mediawiki, Ubuntu:Pro:20.04:LTS: mediawiki, Ubuntu:Pro:22.04:LTS: mediawiki, Ubuntu:Pro:24.04:LTS: mediawiki, Ubuntu:26.04:LTS: mediawiki&lt;/p&gt;
&lt;p&gt;XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mediawiki, Ubuntu:Pro:20.04:LTS: mediawiki, Ubuntu:Pro:22.04:LTS: mediawiki, Ubuntu:Pro:24.04:LTS: mediawiki, Ubuntu:26.04:LTS: mediawiki&lt;/p&gt;
&lt;p&gt;XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-103044</guid>
      <pubDate>Tue, 29 Sep 2026 23:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-102586</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102586</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim&amp;#39;s browser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim&amp;#39;s browser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102586</guid>
      <pubDate>Wed, 30 Sep 2026 09:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-102582</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102582</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102582</guid>
      <pubDate>Wed, 30 Sep 2026 09:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-102581</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102581</guid>
      <pubDate>Wed, 30 Sep 2026 09:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-102580</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102580</guid>
      <pubDate>Wed, 30 Sep 2026 09:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-102578</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102578</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: moodle, Ubuntu:Pro:18.04:LTS: moodle&lt;/p&gt;
&lt;p&gt;A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102578</guid>
      <pubDate>Wed, 30 Sep 2026 09:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-100830</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-100830</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-100830</guid>
      <pubDate>Tue, 29 Sep 2026 13:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-100829</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-100829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-100829</guid>
      <pubDate>Tue, 29 Sep 2026 13:17:00 +0000</pubDate>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-100828</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-100828</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the Bookmarks &amp;amp; History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: mozjs52, Ubuntu:18.04:LTS: mozjs38, Ubuntu:20.04:LTS: mozjs68, Ubuntu:20.04:LTS: mozjs52, Ubuntu:22.04:LTS: mozjs102, Ubuntu:22.04:LTS: mozjs78, Ubuntu:22.04:LTS: mozjs91, Ubuntu:22.04:LTS: thunderbird, Ubuntu:24.04:LTS: mozjs102, Ubuntu:24.04:LTS: mozjs115&lt;/p&gt;
&lt;p&gt;Mitigation bypass in the Bookmarks &amp;amp; History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-100828</guid>
      <pubDate>Tue, 29 Sep 2026 13:17:00 +0000</pubDate>
    </item>
  </channel>
</rss>
