<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/drupal/10</id>
  <title>Most recent entries from drupal</title>
  <updated>2026-10-02T07:09:58.006448+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-172</id>
    <title>DRUPAL-CONTRIB-2026-172</title>
    <updated>2026-09-28T18:55:26+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/webform</p>
<p>The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Form submissions may include uploaded files.</p>
<p>The module does not sufficiently force certain uploaded file types to download when served. Under certain site configurations, a file uploaded through a webform could be rendered inline by a browser, resulting in a cross-site scripting vulnerability.</p>
<p>This vulnerability is mitigated by the fact that a user with permission to create or edit webforms must configure the form to allow the affected file extensions, and a user must specifically open the uploaded file.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-172"/>
    <published>2026-09-23T16:26:49+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-191</id>
    <title>DRUPAL-CONTRIB-2026-191</title>
    <updated>2026-09-23T17:33:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/diba_carousel</p>
<p>The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration.</p>
<p>When the "Allow HTML description" option is enabled, slide descriptions are rendered using the raw stored field value instead of the field's rendered output. This bypasses Drupal's text format filtering and output sanitization mechanisms.</p>
<p>This vulnerability affects sites that use a formatted text field as the carousel description source and have enabled the "Allow HTML description" option.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-191"/>
    <published>2026-09-23T17:24:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-187</id>
    <title>DRUPAL-CONTRIB-2026-187</title>
    <updated>2026-09-23T17:31:31+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/ai_ckeditor</p>
<p>This module enables you to use AI to fill in or replace text in CKEditor.</p>
<p>The module doesn't sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-187"/>
    <published>2026-09-23T17:20:32+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-188</id>
    <title>DRUPAL-CONTRIB-2026-188</title>
    <updated>2026-09-23T17:30:51+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/combined_image_style</p>
<p>This module enables you to combine multiple image styles into a single image derivative.</p>
<p>The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.</p>
<p>Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.</p>
<p>This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-188"/>
    <published>2026-09-23T17:21:51+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-189</id>
    <title>DRUPAL-CONTRIB-2026-189</title>
    <updated>2026-09-23T17:28:12+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/css_usage_analyzer</p>
<p>This module lets a frontend scanner post CSS-usage measurements to the site so admin reports can show real-page statistics.</p>
<p>This module doesn't sufficiently protect the `/css-usage-analyzer/save` endpoint against forged or repeated submissions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-189"/>
    <published>2026-09-23T17:22:38+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-190</id>
    <title>DRUPAL-CONTRIB-2026-190</title>
    <updated>2026-09-23T17:27:26+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/smart_content</p>
<p>This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.</p>
<p>The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint.</p>
<p>This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-190"/>
    <published>2026-09-23T17:23:37+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-186</id>
    <title>DRUPAL-CONTRIB-2026-186</title>
    <updated>2026-09-23T17:23:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/webform_rest</p>
<p>This module enables you to retrieve and submit webforms via REST.</p>
<p>The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-186"/>
    <published>2026-09-23T17:19:41+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-185</id>
    <title>DRUPAL-CONTRIB-2026-185</title>
    <updated>2026-09-23T17:21:55+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/editoria11y</p>
<p>This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.</p>
<p>The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-185"/>
    <published>2026-09-23T17:18:31+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-184</id>
    <title>DRUPAL-CONTRIB-2026-184</title>
    <updated>2026-09-23T17:14:48+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/tawk_to</p>
<p>This module provides integration of the tawk.to live chat for Drupal sites.</p>
<p>The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-184"/>
    <published>2026-09-23T17:14:48+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-182</id>
    <title>DRUPAL-CONTRIB-2026-182</title>
    <updated>2026-09-23T17:11:39+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/rest_api_authentication</p>
<p>This module enables you to add an extra authentication layer to the API.</p>
<p>The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2026-182"/>
    <published>2026-09-23T17:10:00+00:00</published>
  </entry>
</feed>
