<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 18:49:33 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2025-027</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2025-027</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tacjs&lt;/p&gt;
&lt;p&gt;This module enables sites to comply with the European cookie law using tarteaucitron.js.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter user-supplied markup inside of content leading to a persistent Cross Site Scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tacjs&lt;/p&gt;
&lt;p&gt;This module enables sites to comply with the European cookie law using tarteaucitron.js.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter user-supplied markup inside of content leading to a persistent Cross Site Scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2025-027</guid>
    </item>
    <item>
      <title>EUVD-2026-244221</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244221</link>
      <description>EUVD-2026-244221</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244221</guid>
    </item>
    <item>
      <title>fkie_cve-2025-31476</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31476</link>
      <description>&lt;p&gt;tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site&amp;#39;s source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site&amp;#39;s source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-31476</guid>
    </item>
    <item>
      <title>GHSA-p5g4-v748-6fh8 — tarteaucitron.js allows url scheme injection via unfiltered inputs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p5g4-v748-6fh8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tarteaucitronjs&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in `tarteaucitron.js`, allowing a user with high privileges (access to the site&amp;#39;s source code or a CMS plugin) to enter a URL containing an insecure scheme such as `javascript:alert()`. Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to:
- Execution of arbitrary JavaScript code
- Theft of sensitive data through phishing attacks
- Modification of the user interface behavior&lt;/p&gt;
&lt;p&gt;## Fix https://github.com/AmauriC/tarteaucitron.js/commit/2fa1e01023bce2e4b813200600bb1619d56ceb02
The issue was resolved by enforcing strict URL validation, ensuring that they start with `http://` or `https://` before being used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tarteaucitronjs&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in `tarteaucitron.js`, allowing a user with high privileges (access to the site&amp;#39;s source code or a CMS plugin) to enter a URL containing an insecure scheme such as `javascript:alert()`. Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link.&lt;/p&gt;
&lt;p&gt;## Impact
An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to:
- Execution of arbitrary JavaScript code
- Theft of sensitive data through phishing attacks
- Modification of the user interface behavior&lt;/p&gt;
&lt;p&gt;## Fix https://github.com/AmauriC/tarteaucitron.js/commit/2fa1e01023bce2e4b813200600bb1619d56ceb02
The issue was resolved by enforcing strict URL validation, ensuring that they start with `http://` or `https://` before being used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p5g4-v748-6fh8</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0690 — Drupal: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting-Schwachstellen auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsmaßnahmen zu umgehen und Cross-Site-Scripting-Schwachstellen auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0690</guid>
    </item>
  </channel>
</rss>
