<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
    <url>
        <loc>https://patchbriefing.com/php-packages/cve-2026-107848-contao-csrf-backend-actions</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:05:28+02:00</news:publication_date>
            <news:title>CVE-2026-107848 — Contao: CSRF in backend actions</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/cve-2026-107719-fast-jwt-expired-jwt-cache</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:04:55+02:00</news:publication_date>
            <news:title>fast-jwt: Verifier cache accepts expired JWTs (CVE-2026-107719)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/contao-cve-2026-107851-tableaccessvoter</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:04:32+02:00</news:publication_date>
            <news:title>Contao: improper access control in TableAccessVoter (CVE-2026-107851)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/contao-preview-links-cve-2026-107850</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:04:06+02:00</news:publication_date>
            <news:title>Contao: Improper access control in preview links (CVE-2026-107850)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/msgpack5-decoding-negative-int64-mutate-input-buffer-cve-2026-107296</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:03:40+02:00</news:publication_date>
            <news:title>msgpack5: Decoding negative int64 mutates input buffer (CVE-2026-107296)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/enshrined-svg-sanitize-cve-2026-107380</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:03:16+02:00</news:publication_date>
            <news:title>CVE-2026-107380: Stored XSS in enshrined/svg-sanitize via DTD entity / HTML5 named character reference collision</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/fast-jwt-clocktolerance-infinity-bypass-cve-2026-107721</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:02:44+02:00</news:publication_date>
            <news:title>fast-jwt: clockTolerance = Infinity bypasses exp/nbf and persists in verifier cache (CVE-2026-107721)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/music-metadata-ebml-vint-memory-exhaustion</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:02:14+02:00</news:publication_date>
            <news:title>music-metadata: EBML VINT length trusted, allowing memory exhaustion (CVE-2026-107389)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/music-metadata-apev2-uncontrolled-memory-allocation-cve-2026-107387</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-10T20:01:46+02:00</news:publication_date>
            <news:title>music-metadata: Uncontrolled memory allocation in APEv2 parser (CVE-2026-107387)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/cve-2026-108259-tinacms-cli-branch-name-code-injection</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:56:52+02:00</news:publication_date>
            <news:title>CVE-2026-108259 — Code injection in @tinacms/cli from unescaped Git branch name</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/cve-2026-108261-tinacms-admin-preview-origin-fragment</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:56:48+02:00</news:publication_date>
            <news:title>CVE-2026-108261 — TinaCMS admin preview can load attacker origin via URL fragment</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/nodejs-npm/cve-2026-108260-tinacms-tina-markdown-stored-xss</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:56:45+02:00</news:publication_date>
            <news:title>CVE-2026-108260: stored XSS in @tinacms/web-components (tina-markdown)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/contao-search-index-disclosure-cve-2026-107842</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:54:09+02:00</news:publication_date>
            <news:title>Contao search index disclosure — CVE-2026-107842</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/cve-2026-107843-contao-registration-resend-activation-mails</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:54:04+02:00</news:publication_date>
            <news:title>CVE-2026-107843 — Contao registration module re-sends activation mails</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/cve-2026-107844-contao-imagescontroller-path-traversal</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:53:55+02:00</news:publication_date>
            <news:title>Contao path-traversal in ImagesController (CVE-2026-107844)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/php-packages/cve-2026-107845-contao-comments-bundle-xss</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T20:53:50+02:00</news:publication_date>
            <news:title>CVE-2026-107845 — XSS in contao/comments-bundle exposes backend when moderators view comments</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/browsers/google-chrome-154-0-8037-151-chromeos-16805-33-0</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T16:46:54+02:00</news:publication_date>
            <news:title>Google Chrome 154.0.8037.151 (ChromeOS Stable, OS 16805.33.0)</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/wordpress/cve-2026-101324-fluent-forms-reflected-xss</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T00:00:00+02:00</news:publication_date>
            <news:title>CVE-2026-101324 — Fluent Forms reflected XSS via {get.*} in Custom HTML fields</news:title>
        </news:news>
    </url>
    <url>
        <loc>https://patchbriefing.com/wordpress/wp-rocket-cve-2026-97076-cve-2026-97075</loc>
        <news:news>
            <news:publication>
                <news:name>PatchBriefing</news:name>
                <news:language>en</news:language>
            </news:publication>
            <news:publication_date>2026-10-09T00:00:00+02:00</news:publication_date>
            <news:title>WP Rocket: CVE-2026-97076 and CVE-2026-97075</news:title>
        </news:news>
    </url>
</urlset>
