<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:54:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-05545</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-05545</link>
      <description>bdu:2020-05545</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-05545</guid>
    </item>
    <item>
      <title>BIT-drupal-2020-13671</title>
      <link>https://cve.radiocsirt.org/vuln/bit-drupal-2020-13671</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: drupal&lt;/p&gt;
&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: drupal&lt;/p&gt;
&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-drupal-2020-13671</guid>
    </item>
    <item>
      <title>certfr-2020-avi-760 — Une vulnérabilité a été découverte dans Drupal Core. Elle permet à un
attaquant de provoquer une exécution de code arbi…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-760</link>
      <description>certfr-2020-avi-760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-760</guid>
    </item>
    <item>
      <title>cnvd-2020-64563</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-64563</link>
      <description>cnvd-2020-64563</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-64563</guid>
    </item>
    <item>
      <title>EUVD-2026-256049</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256049</link>
      <description>EUVD-2026-256049</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256049</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13671</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13671</link>
      <description>&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13671</guid>
    </item>
    <item>
      <title>GHSA-68jc-v27h-vhmw — Drupal core Unrestricted Upload of File with Dangerous Type</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68jc-v27h-vhmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: drupal/core, Packagist: drupal/drupal&lt;/p&gt;
&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: drupal/core, Packagist: drupal/drupal&lt;/p&gt;
&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68jc-v27h-vhmw</guid>
    </item>
    <item>
      <title>gsd-2020-13671</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13671</link>
      <description>gsd-2020-13671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13671</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13671</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13671</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:Pro:16.04:LTS: drupal7&lt;/p&gt;
&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: drupal7, Ubuntu:Pro:16.04:LTS: drupal7&lt;/p&gt;
&lt;p&gt;Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13671</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1938 — Drupal: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1938</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Drupal ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Drupal ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1938</guid>
    </item>
  </channel>
</rss>
