<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:28:31 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2026-108</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-108</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/datafield&lt;/p&gt;
&lt;p&gt;This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/datafield&lt;/p&gt;
&lt;p&gt;This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-108</guid>
    </item>
    <item>
      <title>EUVD-2026-363303</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363303</link>
      <description>EUVD-2026-363303</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363303</guid>
    </item>
    <item>
      <title>fkie_cve-2026-81269</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-81269</link>
      <description>&lt;p&gt;Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-81269</guid>
    </item>
    <item>
      <title>GHSA-rq35-w8f7-p43g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rq35-w8f7-p43g</link>
      <description>&lt;p&gt;Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rq35-w8f7-p43g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3041 — Drupal Extensions: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3041</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um Sicherheitsmaßnahmen zu umgehen, sensible Informationen offenzulegen, Daten zu manipulieren und Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um Sicherheitsmaßnahmen zu umgehen, sensible Informationen offenzulegen, Daten zu manipulieren und Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3041</guid>
    </item>
  </channel>
</rss>
