<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/drupal/10</id>
  <title>Most recent entries from drupal</title>
  <updated>2026-10-02T09:39:16.397966+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-082</id>
    <title>DRUPAL-CONTRIB-2017-082</title>
    <updated>2023-08-21T13:31:01+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/permissions_by_term</p>
<p>The Permissions by Term module extends Drupal by adding functionality for restricting access to single nodes via taxonomy terms.</p>
<p>The module grants access to nodes that are being blocked by other node access modules and that the Permissions by Term module does not intend to control. Additionally, it grants access to unpublished nodes in node listings to users who should not be able to see them. These problems lead to an access bypass vulnerability.</p>
<p>This vulnerability is mitigated by the fact that it only occurs on sites that either have another node access module (besides Permissions by Term) in use, or that have node listings that are accessible to unprivileged users and that don't directly filter out unpublished content.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2017-082"/>
    <published>2017-11-08T17:16:30+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-083</id>
    <title>DRUPAL-CONTRIB-2017-083</title>
    <updated>2023-08-21T13:31:18+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/config_perms</p>
<p>Custom Permissions is a lightweight module that allows permissions to be created and managed through an administrative form.</p>
<p>When this module is in use, any user who is able to perform an action which rebuilds some of Drupal's caches can trigger a scenario in which certain pages protected by this module's custom permissions temporarily lose those custom access controls, thereby leading to an access bypass vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2017-083"/>
    <published>2017-11-08T17:22:08+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-091</id>
    <title>DRUPAL-CONTRIB-2017-091</title>
    <updated>2023-08-21T13:26:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/config_update</p>
<p>The Configuration Update Reports sub-module in the Configuration Update module project enables you to run reports to see what configuration on your site differs from the configuration distributed by a module, theme, or installation profile, and to revert, delete, or import configuration.</p>
<p>This module doesn't sufficiently protect the Import operation, thereby exposing a Cross Site Request Forgery (CSRF) vulnerability which can be exploited by unprivileged users to trick an administrator into unwanted import of configuration.</p>
<p>This vulnerability is mitigated by the fact that only configuration items distributed with a module, theme, or installation profile that is currently installed and enabled on the site can be imported, not arbitrary configuration values.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2017-091"/>
    <published>2017-12-06T18:44:03+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-094</id>
    <title>DRUPAL-CONTRIB-2017-094</title>
    <updated>2023-08-21T13:28:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/link_click_count</p>
<p>The Link Click Count module helps you to monitor the traffic to your website by creating link fields. These link fields can be individual links or internal/external links that can be added to the content type.</p>
<p>The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. The security team takes action in cases like this without regard to the severity of the security issue in question. If you would like to maintain this module, please read: &lt;https://www.drupal.org/node/251466&gt;</p>
<p>All projects that are being marked unsupported are given a score of critical. Code that is no longer maintained poses a threat to securing sites.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2017-094"/>
    <published>2017-12-20T14:12:47+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-001</id>
    <title>DRUPAL-CONTRIB-2018-001</title>
    <updated>2023-08-11T21:45:33+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/stacks</p>
<p>This module enables content editors to create complex pages and layouts on the fly without the help from a developer, using reusable widgets.</p>
<p>The module does not sufficiently filter values posted to its AJAX endpoint, which leads to the instantiation of an arbitrary PHP class.</p>
<p>This vulnerability is mitigated by the fact that only sites with the Stacks - Content Feed submodule enabled are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2018-001"/>
    <published>2018-01-10T17:57:53+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-002</id>
    <title>DRUPAL-CONTRIB-2018-002</title>
    <updated>2023-08-11T21:46:04+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/node_view_permissions</p>
<p>The Node view permissions module enables the "View own content" and "View any content" permissions for each content type on the permissions page.</p>
<p>This module has a vulnerability that allows users with these permissions to view unpublished content that they are not otherwise authorized to view.</p>
<p>**This issue was fixed by the maintainer outside of the normal security team protocols. Some issues were patched in 2014 for the 7.x version of this module. The 8.x release was updated within the last 6 months. Both are now flagged as security updates.**</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2018-002"/>
    <published>2018-01-10T18:02:19+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-008</id>
    <title>DRUPAL-CONTRIB-2018-008</title>
    <updated>2023-08-11T21:41:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/entity_ref_tab_formatter</p>
<p>This module enables you to show referenced entities in tabs.</p>
<p>The module doesn't sufficiently sanitize the body fields of the referenced entities when it prints them to the tabs.</p>
<p>This vulnerability is mitigated by the fact that an attacker must have a role with the permission create/edit content of the content type that is referenced.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2018-008"/>
    <published>2018-02-07T18:45:12+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-014</id>
    <title>DRUPAL-CONTRIB-2018-014</title>
    <updated>2023-08-11T21:43:18+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/ckeditor_uploadimage</p>
<p>This module enables you to drag and drop or paste images into CKEditor.  
The module does not sufficiently verify users permissions, which leads to anonymous users being able to upload files to the server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2018-014"/>
    <published>2018-02-21T19:04:59+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-015</id>
    <title>DRUPAL-CONTRIB-2018-015</title>
    <updated>2023-08-11T21:43:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/jsonapi</p>
<p>This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.</p>
<p>* The module doesn't sufficiently associate cacheability metadata in certain situations thereby causing an access bypass vulnerability.</p>
<p>This vulnerability is mitigated by the fact that an attacker cannot trigger an exploitable situation themselves.
* The module doesn't sufficiently check access in certain situations.</p>
<p>This vulnerability is mitigated by the fact that an attacker must have permission to create entities of certain content entity types.</p>
<p>#### Update: This is fixed in 8.x-1.10 not 8.x-1.9</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2018-015"/>
    <published>2018-02-21T20:12:22+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-016</id>
    <title>DRUPAL-CONTRIB-2018-016</title>
    <updated>2023-08-11T21:44:04+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist:https://packages.drupal.org/8: drupal/jsonapi</p>
<p>This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.</p>
<p>The module doesn't sufficiently check access when viewing related resources or relationships, thereby causing an access bypass vulnerability.</p>
<p>This vulnerability is mitigated by the fact that an attacker must be allowed to view the related data, otherwise all they can glean is an entity type UUID and a UUID, which are meaningless by themselves.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/drupal-contrib-2018-016"/>
    <published>2018-03-21T16:59:32+00:00</published>
  </entry>
</feed>
