<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:51:16 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2025-099</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-099</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/facets&lt;/p&gt;
&lt;p&gt;This module enables you to to easily create and manage faceted search interfaces.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access to entities when they are displayed as facets.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only sites that show facets with entity labels (like taxonomy terms) are affected, and only if some of those entities are unpublished or have other access restrictions.&lt;/p&gt;
&lt;p&gt;**CVSS risk score ([experimental](https://www.drupal.org/project/securitydrupalorg/issues/3442181)) 6.9 / Medium**&lt;/p&gt;
&lt;p&gt;[CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/facets&lt;/p&gt;
&lt;p&gt;This module enables you to to easily create and manage faceted search interfaces.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access to entities when they are displayed as facets.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only sites that show facets with entity labels (like taxonomy terms) are affected, and only if some of those entities are unpublished or have other access restrictions.&lt;/p&gt;
&lt;p&gt;**CVSS risk score ([experimental](https://www.drupal.org/project/securitydrupalorg/issues/3442181)) 6.9 / Medium**&lt;/p&gt;
&lt;p&gt;[CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2025-099</guid>
    </item>
    <item>
      <title>EUVD-2026-255173</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255173</link>
      <description>EUVD-2026-255173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255173</guid>
    </item>
    <item>
      <title>fkie_cve-2025-9549</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9549</link>
      <description>&lt;p&gt;Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-9549</guid>
    </item>
    <item>
      <title>GHSA-q59x-44mh-c286</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q59x-44mh-c286</link>
      <description>&lt;p&gt;Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q59x-44mh-c286</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1918 — Drupal Extensions: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1918</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Extensions ausnutzen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Extensions ausnutzen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1918</guid>
    </item>
  </channel>
</rss>
