<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:00:08 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2026-022</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-022</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ajax_dashboard&lt;/p&gt;
&lt;p&gt;AJAX Dashboard: Entity Dashboards enables you to create configurable dashboards attached to entities which include AJAX-reloading of a main content area based on inputs from a configurable set of buttons.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access on the dashboard configuration route. Unauthorized users could access the entity dashboard configuration page and either enable or disable dashboards. The affected administration page does not permit editing the configurations of the dashboards themselves.&lt;/p&gt;
&lt;p&gt;The vulnerability is mitigated by the fact that the AJAX Dashboard Entity Dashboard submodule must be enabled.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ajax_dashboard&lt;/p&gt;
&lt;p&gt;AJAX Dashboard: Entity Dashboards enables you to create configurable dashboards attached to entities which include AJAX-reloading of a main content area based on inputs from a configurable set of buttons.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access on the dashboard configuration route. Unauthorized users could access the entity dashboard configuration page and either enable or disable dashboards. The affected administration page does not permit editing the configurations of the dashboards themselves.&lt;/p&gt;
&lt;p&gt;The vulnerability is mitigated by the fact that the AJAX Dashboard Entity Dashboard submodule must be enabled.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-022</guid>
    </item>
    <item>
      <title>EUVD-2026-277834</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277834</link>
      <description>EUVD-2026-277834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277834</guid>
    </item>
    <item>
      <title>fkie_cve-2026-3527</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3527</link>
      <description>&lt;p&gt;Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AJAX Dashboard: from 0.0.0 before 3.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AJAX Dashboard: from 0.0.0 before 3.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-3527</guid>
    </item>
    <item>
      <title>GHSA-c3p6-9m4j-2c45</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c3p6-9m4j-2c45</link>
      <description>&lt;p&gt;Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AJAX Dashboard: from 0.0.0 before 3.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AJAX Dashboard: from 0.0.0 before 3.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c3p6-9m4j-2c45</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0599 — Drupal Extensions: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0599</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal-Erweiterungen ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal-Erweiterungen ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0599</guid>
    </item>
  </channel>
</rss>
