<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:49:35.199503+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-027</id>
    <title>DRUPAL-CONTRIB-2025-027</title>
    <updated>2026-10-07T18:49:35.203848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/tacjs</p>
<p>This module enables sites to comply with the European cookie law using tarteaucitron.js.</p>
<p>The module doesn't sufficiently filter user-supplied markup inside of content leading to a persistent Cross Site Scripting (XSS) vulnerability.</p>
<p>This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2025-027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-244221</id>
    <title>EUVD-2026-244221</title>
    <updated>2026-10-07T18:49:35.203911+00:00</updated>
    <content>EUVD-2026-244221</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-244221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31476</id>
    <title>fkie_cve-2025-31476</title>
    <updated>2026-10-07T18:49:35.203928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-31476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p5g4-v748-6fh8</id>
    <title>GHSA-p5g4-v748-6fh8 — tarteaucitron.js allows url scheme injection via unfiltered inputs</title>
    <updated>2026-10-07T18:49:35.203954+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tarteaucitronjs</p>
<p>A vulnerability was identified in `tarteaucitron.js`, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as `javascript:alert()`. Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link.</p>
<p>## Impact
An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to:
- Execution of arbitrary JavaScript code
- Theft of sensitive data through phishing attacks
- Modification of the user interface behavior</p>
<p>## Fix https://github.com/AmauriC/tarteaucitron.js/commit/2fa1e01023bce2e4b813200600bb1619d56ceb02
The issue was resolved by enforcing strict URL validation, ensuring that they start with `http://` or `https://` before being used.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p5g4-v748-6fh8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690</id>
    <title>WID-SEC-W-2025-0690 — Drupal: Mehrere Schwachstellen</title>
    <updated>2026-10-07T18:49:35.203981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting-Schwachstellen auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690"/>
  </entry>
</feed>
