<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:51:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-00851</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-00851</link>
      <description>bdu:2025-00851</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-00851</guid>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2024-029</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2024-029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/opigno_learning_path&lt;/p&gt;
&lt;p&gt;The Opigno Learning Path module enables you to manage group content.&lt;/p&gt;
&lt;p&gt;Administrative forms allow uploading malicious files which may contain arbitrary code (RCE) or cross site scriptiong (XSS). These forms were not adequately controlled with permissions that communicate the severity of the permission.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission &amp;#34;Manage group content in any group&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/opigno_learning_path&lt;/p&gt;
&lt;p&gt;The Opigno Learning Path module enables you to manage group content.&lt;/p&gt;
&lt;p&gt;Administrative forms allow uploading malicious files which may contain arbitrary code (RCE) or cross site scriptiong (XSS). These forms were not adequately controlled with permissions that communicate the severity of the permission.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission &amp;#34;Manage group content in any group&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2024-029</guid>
    </item>
    <item>
      <title>EUVD-2026-210438</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210438</link>
      <description>EUVD-2026-210438</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210438</guid>
    </item>
    <item>
      <title>fkie_cve-2024-13265</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-13265</link>
      <description>&lt;p&gt;Improper Neutralization of Directives in Statically Saved Code (&amp;#39;Static Code Injection&amp;#39;) vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Neutralization of Directives in Statically Saved Code (&amp;#39;Static Code Injection&amp;#39;) vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-13265</guid>
    </item>
    <item>
      <title>GHSA-2rx4-vrv5-3mjp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2rx4-vrv5-3mjp</link>
      <description>&lt;p&gt;Improper Neutralization of Directives in Statically Saved Code (&amp;#39;Static Code Injection&amp;#39;) vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Neutralization of Directives in Statically Saved Code (&amp;#39;Static Code Injection&amp;#39;) vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2rx4-vrv5-3mjp</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1791 — Drupal: Mehrere Schwachstellen ermöglichen Codeausführung und Cross Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1791</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um beliebigen Programmcode auszuführen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um beliebigen Programmcode auszuführen und einen Cross-Site-Scripting-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1791</guid>
    </item>
  </channel>
</rss>
