<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:20:02 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2025-028</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-028</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/access_code&lt;/p&gt;
&lt;p&gt;This module enables users to log in using a short access code instead of providing a username/password combination.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently protect against brute force attacks to guess a user&amp;#39;s access code.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that access code based logins are off by default and only enabled for accounts that enable it. Sites could mitigate the issue without updating by:&lt;/p&gt;
&lt;p&gt;1. disabling the access code login method for critical accounts
2. monitor and prevent brute force attacks in other ways (for example, with a Web Application Firewall)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/access_code&lt;/p&gt;
&lt;p&gt;This module enables users to log in using a short access code instead of providing a username/password combination.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently protect against brute force attacks to guess a user&amp;#39;s access code.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that access code based logins are off by default and only enabled for accounts that enable it. Sites could mitigate the issue without updating by:&lt;/p&gt;
&lt;p&gt;1. disabling the access code login method for critical accounts
2. monitor and prevent brute force attacks in other ways (for example, with a Web Application Firewall)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2025-028</guid>
    </item>
    <item>
      <title>EUVD-2026-229806</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-229806</link>
      <description>EUVD-2026-229806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-229806</guid>
    </item>
    <item>
      <title>fkie_cve-2025-3129</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3129</link>
      <description>&lt;p&gt;Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-3129</guid>
    </item>
    <item>
      <title>GHSA-9qmr-4gv6-xmf3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9qmr-4gv6-xmf3</link>
      <description>&lt;p&gt;Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9qmr-4gv6-xmf3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0690 — Drupal: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting-Schwachstellen auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting-Schwachstellen auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690</guid>
    </item>
  </channel>
</rss>
