<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:51:08.555481+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00851</id>
    <title>bdu:2025-00851</title>
    <updated>2026-10-03T05:51:08.559936+00:00</updated>
    <content>bdu:2025-00851</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2024-029</id>
    <title>DRUPAL-CONTRIB-2024-029</title>
    <updated>2026-10-03T05:51:08.559967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/opigno_learning_path</p>
<p>The Opigno Learning Path module enables you to manage group content.</p>
<p>Administrative forms allow uploading malicious files which may contain arbitrary code (RCE) or cross site scriptiong (XSS). These forms were not adequately controlled with permissions that communicate the severity of the permission.</p>
<p>This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Manage group content in any group".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2024-029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-210438</id>
    <title>EUVD-2026-210438</title>
    <updated>2026-10-03T05:51:08.560002+00:00</updated>
    <content>EUVD-2026-210438</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-210438"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-13265</id>
    <title>fkie_cve-2024-13265</title>
    <updated>2026-10-03T05:51:08.560015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-13265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2rx4-vrv5-3mjp</id>
    <title>GHSA-2rx4-vrv5-3mjp</title>
    <updated>2026-10-03T05:51:08.560035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2rx4-vrv5-3mjp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1791</id>
    <title>WID-SEC-W-2024-1791 — Drupal: Mehrere Schwachstellen ermöglichen Codeausführung und Cross Site Scripting</title>
    <updated>2026-10-03T05:51:08.560050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um beliebigen Programmcode auszuführen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1791"/>
  </entry>
</feed>
