<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/cve-2026-107848-contao-csrf-backend-acties</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:05:28+02:00</news:publication_date>
            <news:title>CVE-2026-107848 — Contao: CSRF bij backend-acties</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/cve-2026-107719-fast-jwt-verlopen-jwt-cache</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:04:55+02:00</news:publication_date>
            <news:title>fast-jwt: Verifier-cache accepteert verlopen JWT&#039;s (CVE-2026-107719)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/contao-cve-2026-107851-tableaccessvoter</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:04:32+02:00</news:publication_date>
            <news:title>Contao: onjuiste toegangscontrole in TableAccessVoter (CVE-2026-107851)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/contao-preview-links-cve-2026-107850</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:04:06+02:00</news:publication_date>
            <news:title>Contao: Onjuiste toegangscontrole in preview-links (CVE-2026-107850)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/msgpack5-decoderen-negatieve-int64-verandert-invoerbuffer-cve-2026-107296</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:03:40+02:00</news:publication_date>
            <news:title>msgpack5: Decoderen van negatieve int64 verandert de invoerbuffer (CVE-2026-107296)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/enshrined-svg-sanitize-cve-2026-107380</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:03:16+02:00</news:publication_date>
            <news:title>CVE-2026-107380: Stored XSS in enshrined/svg-sanitize via DTD-entiteit en HTML5 named character reference-collision</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/fast-jwt-clocktolerance-infinity-omzeiling-cve-2026-107721</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:02:44+02:00</news:publication_date>
            <news:title>fast-jwt: clockTolerance = Infinity omzeilt exp/nbf en blijft in verifier-cache (CVE-2026-107721)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/music-metadata-ebml-vint-geheugenuitputting</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:02:14+02:00</news:publication_date>
            <news:title>music-metadata: EBML VINT-lengte vertrouwd, waardoor geheugenuitputting mogelijk is (CVE-2026-107389)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/music-metadata-apev2-ongecontroleerde-geheugenallocatie-cve-2026-107387</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:01:46+02:00</news:publication_date>
            <news:title>music-metadata: Ongecontroleerde geheugenallocatie in APEv2-parser (CVE-2026-107387)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/cve-2026-108259-tinacms-cli-branch-code-injectie</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:56:52+02:00</news:publication_date>
            <news:title>CVE-2026-108259 — Code-injectie in @tinacms/cli via ongevangen Git-branchnaam</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/cve-2026-108261-tinacms-admin-preview-origin-fragment-nl</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:56:48+02:00</news:publication_date>
            <news:title>CVE-2026-108261 — TinaCMS admin-preview laadt aanvallers‑origin uit URL-fragment</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/nodejs-npm/cve-2026-108260-tinacms-tina-markdown-opgeslagen-xss</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:56:45+02:00</news:publication_date>
            <news:title>CVE-2026-108260: opgeslagen XSS in @tinacms/web-components (tina-markdown)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/contao-zoekindex-lek-cve-2026-107842</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:54:09+02:00</news:publication_date>
            <news:title>Contao zoekindex-lek — CVE-2026-107842</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/cve-2026-107843-contao-registratie-herstuur-activatiemails</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:54:04+02:00</news:publication_date>
            <news:title>CVE-2026-107843 — Contao registratie-module stuurt activatiemails opnieuw</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/cve-2026-107844-contao-imagescontroller-pad-traversal</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:53:55+02:00</news:publication_date>
            <news:title>Contao pad‑traversal in ImagesController (CVE-2026-107844)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/php-packages/cve-2026-107845-contao-comments-bundle-xss</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:53:50+02:00</news:publication_date>
            <news:title>CVE-2026-107845 — XSS in contao/comments-bundle kan backend blootstellen bij weergave van reacties</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/browsers/google-chrome-154-0-8037-151-chromeos-16805-33-0-nl</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T16:46:54+02:00</news:publication_date>
            <news:title>Google Chrome 154.0.8037.151 (ChromeOS Stable, OS 16805.33.0)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/wordpress/cve-2026-101324-fluent-forms-reflected-xss-nl</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T00:00:00+02:00</news:publication_date>
            <news:title>CVE-2026-101324 — Fluent Forms reflected XSS via {get.*} in Custom HTML-velden</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nl/wordpress/wp-rocket-cve-2026-97076-cve-2026-97075</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>nl</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T00:00:00+02:00</news:publication_date>
            <news:title>WP Rocket: CVE-2026-97076 en CVE-2026-97075</news:title>
        </news:news>
    </url>
</urlset>
