<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:54:12 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2025-060</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-060</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/single_content_sync&lt;/p&gt;
&lt;p&gt;This module enables you to seamlessly migrate and deploy content across environments, eliminating manual steps. It simplifies the process by exporting content to a YML file or a ZIP archive, which can be imported into another environment effortlessly.&lt;/p&gt;
&lt;p&gt;While the export feature rightfully bypasses implemented access controls, enabling it to extract all entity data, including private and confidential information, to the mentioned formats, it fails to adequately safeguard the generated output.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission &amp;#34;export single content&amp;#34; or &amp;#34;Allow user to export all content&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/single_content_sync&lt;/p&gt;
&lt;p&gt;This module enables you to seamlessly migrate and deploy content across environments, eliminating manual steps. It simplifies the process by exporting content to a YML file or a ZIP archive, which can be imported into another environment effortlessly.&lt;/p&gt;
&lt;p&gt;While the export feature rightfully bypasses implemented access controls, enabling it to extract all entity data, including private and confidential information, to the mentioned formats, it fails to adequately safeguard the generated output.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission &amp;#34;export single content&amp;#34; or &amp;#34;Allow user to export all content&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2025-060</guid>
    </item>
    <item>
      <title>EUVD-2026-240686</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-240686</link>
      <description>EUVD-2026-240686</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-240686</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48009</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48009</link>
      <description>&lt;p&gt;Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48009</guid>
    </item>
    <item>
      <title>GHSA-rxf3-624f-c767</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rxf3-624f-c767</link>
      <description>&lt;p&gt;Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rxf3-624f-c767</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1065 — Drupal Extensions: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1065</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen preiszugeben, Sicherheitsmaßnahmen zu umgehen und andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen preiszugeben, Sicherheitsmaßnahmen zu umgehen und andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1065</guid>
    </item>
  </channel>
</rss>
