<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:37:09.978052+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-067</id>
    <title>DRUPAL-CONTRIB-2026-067</title>
    <updated>2026-10-04T14:37:09.980995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/flowdrop</p>
<p>This module enables you to test and run AI-driven workflows interactively through a chat interface.</p>
<p>The module doesn't sufficiently enforce permissions on certain endpoints. Attackers may be able to trigger workflow execution (incurring LLM spend and tool side effects) or send messages into other user's sessions.</p>
<p>This vulnerability is mitigated by the fact that an attacker must have the permission "View any session", which is not granted to anonymous or authenticated users by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336088</id>
    <title>EUVD-2026-336088</title>
    <updated>2026-10-04T14:37:09.981048+00:00</updated>
    <content>EUVD-2026-336088</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-58589</id>
    <title>fkie_cve-2026-58589</title>
    <updated>2026-10-04T14:37:09.981064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-58589"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wfpx-3cw4-cw3g</id>
    <title>GHSA-wfpx-3cw4-cw3g</title>
    <updated>2026-10-04T14:37:09.981085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wfpx-3cw4-cw3g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2181</id>
    <title>WID-SEC-W-2026-2181 — Drupal Extensions: Mehrere Schwachstellen</title>
    <updated>2026-10-04T14:37:09.981099+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2181"/>
  </entry>
</feed>
