<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:41:14.392333+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-109</id>
    <title>DRUPAL-CONTRIB-2025-109</title>
    <updated>2026-10-07T13:41:14.397478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/umami_analytics</p>
<p>This module enables you to add Umami Analytics web statistics tracking system to your website.</p>
<p>The "administer umami analytics" permission allows inserting an arbitrary JavaScript file on every page. While this is an expected feature, the permission lacks the "restrict access" flag, which should alert administrators that this permission is potentially dangerous and can lead to cross-site scripting (XSS) vulnerabilities.</p>
<p>This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer umami analytics”.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2025-109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257184</id>
    <title>EUVD-2026-257184</title>
    <updated>2026-10-07T13:41:14.397554+00:00</updated>
    <content>EUVD-2026-257184</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-10931</id>
    <title>fkie_cve-2025-10931</title>
    <updated>2026-10-07T13:41:14.397576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS).This issue affects Umami Analytics: from 0.0.0 before 1.0.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-10931"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jxp8-4jw5-5xjc</id>
    <title>GHSA-jxp8-4jw5-5xjc — Drupal Umami Analytics allows Cross-Site Scripting (XSS)</title>
    <updated>2026-10-07T13:41:14.397612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: drupal/umami_analytics</p>
<p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS). This issue affects Umami Analytics: from 0.0.0 before 1.0.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jxp8-4jw5-5xjc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2126</id>
    <title>WID-SEC-W-2025-2126 — Drupal Module: Mehrere Schwachstellen</title>
    <updated>2026-10-07T13:41:14.397646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Drupal Module ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um falsche Informationen darzustellen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2126"/>
  </entry>
</feed>
