<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:07:08.608101+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-108</id>
    <title>DRUPAL-CONTRIB-2026-108</title>
    <updated>2026-10-04T04:07:08.702629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/datafield</p>
<p>This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.</p>
<p>The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363303</id>
    <title>EUVD-2026-363303</title>
    <updated>2026-10-04T04:07:08.702720+00:00</updated>
    <content>EUVD-2026-363303</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-81269</id>
    <title>fkie_cve-2026-81269</title>
    <updated>2026-10-04T04:07:08.702744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-81269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rq35-w8f7-p43g</id>
    <title>GHSA-rq35-w8f7-p43g</title>
    <updated>2026-10-04T04:07:08.702779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rq35-w8f7-p43g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3041</id>
    <title>WID-SEC-W-2026-3041 — Drupal Extensions: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:07:08.702804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um Sicherheitsmaßnahmen zu umgehen, sensible Informationen offenzulegen, Daten zu manipulieren und Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3041"/>
  </entry>
</feed>
