<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:16:39 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2026-076</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-076</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ai_seo&lt;/p&gt;
&lt;p&gt;The AI SEO/GEO Analyzer module generates SEO/GEO analysis reports by sending content of an entity (including its comments) to an LLM, then converts the model&amp;#39;s Markdown response to HTML and stores it for display to privileged users.&lt;/p&gt;
&lt;p&gt;The generated HTML was rendered without passing through Drupal&amp;#39;s filtering pipeline, so it relied on the LLM output being safe. Under certain circumstances a crafted prompt injection — planted in content that is included in the analysis — can cause the LLM to emit markup that results in stored Cross-site Scripting when the report is later viewed.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must be able to inject text into the content that is sent to the LLM, and that prompt injection is non-deterministic and not guaranteed to succeed on a given attempt.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ai_seo&lt;/p&gt;
&lt;p&gt;The AI SEO/GEO Analyzer module generates SEO/GEO analysis reports by sending content of an entity (including its comments) to an LLM, then converts the model&amp;#39;s Markdown response to HTML and stores it for display to privileged users.&lt;/p&gt;
&lt;p&gt;The generated HTML was rendered without passing through Drupal&amp;#39;s filtering pipeline, so it relied on the LLM output being safe. Under certain circumstances a crafted prompt injection — planted in content that is included in the analysis — can cause the LLM to emit markup that results in stored Cross-site Scripting when the report is later viewed.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must be able to inject text into the content that is sent to the LLM, and that prompt injection is non-deterministic and not guaranteed to succeed on a given attempt.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-076</guid>
    </item>
    <item>
      <title>EUVD-2026-336150</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336150</link>
      <description>EUVD-2026-336150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336150</guid>
    </item>
    <item>
      <title>fkie_cve-2026-15085</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15085</link>
      <description>&lt;p&gt;Improper Neutralization of Input During Web Page Generation (&amp;#34;Cross-site Scripting&amp;#34;) vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Neutralization of Input During Web Page Generation (&amp;#34;Cross-site Scripting&amp;#34;) vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-15085</guid>
    </item>
    <item>
      <title>GHSA-xg2f-c7h9-qw99</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xg2f-c7h9-qw99</link>
      <description>&lt;p&gt;Improper Neutralization of Input During Web Page Generation (&amp;#34;Cross-site Scripting&amp;#34;) vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Neutralization of Input During Web Page Generation (&amp;#34;Cross-site Scripting&amp;#34;) vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xg2f-c7h9-qw99</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2251 — Drupal Module: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, umSQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, umSQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2251</guid>
    </item>
  </channel>
</rss>
