<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:55:21.530440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-060</id>
    <title>DRUPAL-CONTRIB-2025-060</title>
    <updated>2026-10-03T00:55:21.533859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/single_content_sync</p>
<p>This module enables you to seamlessly migrate and deploy content across environments, eliminating manual steps. It simplifies the process by exporting content to a YML file or a ZIP archive, which can be imported into another environment effortlessly.</p>
<p>While the export feature rightfully bypasses implemented access controls, enabling it to extract all entity data, including private and confidential information, to the mentioned formats, it fails to adequately safeguard the generated output.</p>
<p>This vulnerability is mitigated by the fact that an attacker must have a role with the permission "export single content" or "Allow user to export all content".</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2025-060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-240686</id>
    <title>EUVD-2026-240686</title>
    <updated>2026-10-03T00:55:21.533903+00:00</updated>
    <content>EUVD-2026-240686</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-240686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48009</id>
    <title>fkie_cve-2025-48009</title>
    <updated>2026-10-03T00:55:21.533920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rxf3-624f-c767</id>
    <title>GHSA-rxf3-624f-c767</title>
    <updated>2026-10-03T00:55:21.533940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rxf3-624f-c767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1065</id>
    <title>WID-SEC-W-2025-1065 — Drupal Extensions: Mehrere Schwachstellen</title>
    <updated>2026-10-03T00:55:21.533955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen preiszugeben, Sicherheitsmaßnahmen zu umgehen und andere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1065"/>
  </entry>
</feed>
