<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:50:29.488509+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-034</id>
    <title>DRUPAL-CONTRIB-2026-034</title>
    <updated>2026-10-03T16:50:29.492192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/node_view_permissions</p>
<p>Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page  
The module doesn't sufficiently handle the case where a user is cancelled and their content is reassigned to the anonymous user.  
This vulnerability is mitigated by the fact that only private contents where anonymous should not have view access are affected, and only if a node was reassigned to the anonymous user.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319736</id>
    <title>EUVD-2026-319736</title>
    <updated>2026-10-03T16:50:29.492253+00:00</updated>
    <content>EUVD-2026-319736</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8491</id>
    <title>fkie_cve-2026-8491</title>
    <updated>2026-10-03T16:50:29.492270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.</p>
<p>This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrm3-543w-4g3q</id>
    <title>GHSA-xrm3-543w-4g3q</title>
    <updated>2026-10-03T16:50:29.492296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.</p>
<p>This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrm3-543w-4g3q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1533</id>
    <title>WID-SEC-W-2026-1533 — Drupal Extensions: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:50:29.492312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1533"/>
  </entry>
</feed>
