<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from drupal</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:39:15 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2017-082</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-082</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/permissions_by_term&lt;/p&gt;
&lt;p&gt;The Permissions by Term module extends Drupal by adding functionality for restricting access to single nodes via taxonomy terms.&lt;/p&gt;
&lt;p&gt;The module grants access to nodes that are being blocked by other node access modules and that the Permissions by Term module does not intend to control. Additionally, it grants access to unpublished nodes in node listings to users who should not be able to see them. These problems lead to an access bypass vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that it only occurs on sites that either have another node access module (besides Permissions by Term) in use, or that have node listings that are accessible to unprivileged users and that don&amp;#39;t directly filter out unpublished content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/permissions_by_term&lt;/p&gt;
&lt;p&gt;The Permissions by Term module extends Drupal by adding functionality for restricting access to single nodes via taxonomy terms.&lt;/p&gt;
&lt;p&gt;The module grants access to nodes that are being blocked by other node access modules and that the Permissions by Term module does not intend to control. Additionally, it grants access to unpublished nodes in node listings to users who should not be able to see them. These problems lead to an access bypass vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that it only occurs on sites that either have another node access module (besides Permissions by Term) in use, or that have node listings that are accessible to unprivileged users and that don&amp;#39;t directly filter out unpublished content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2017-082</guid>
      <pubDate>Wed, 08 Nov 2017 17:16:30 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2017-083</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/config_perms&lt;/p&gt;
&lt;p&gt;Custom Permissions is a lightweight module that allows permissions to be created and managed through an administrative form.&lt;/p&gt;
&lt;p&gt;When this module is in use, any user who is able to perform an action which rebuilds some of Drupal&amp;#39;s caches can trigger a scenario in which certain pages protected by this module&amp;#39;s custom permissions temporarily lose those custom access controls, thereby leading to an access bypass vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/config_perms&lt;/p&gt;
&lt;p&gt;Custom Permissions is a lightweight module that allows permissions to be created and managed through an administrative form.&lt;/p&gt;
&lt;p&gt;When this module is in use, any user who is able to perform an action which rebuilds some of Drupal&amp;#39;s caches can trigger a scenario in which certain pages protected by this module&amp;#39;s custom permissions temporarily lose those custom access controls, thereby leading to an access bypass vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2017-083</guid>
      <pubDate>Wed, 08 Nov 2017 17:22:08 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2017-091</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-091</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/config_update&lt;/p&gt;
&lt;p&gt;The Configuration Update Reports sub-module in the Configuration Update module project enables you to run reports to see what configuration on your site differs from the configuration distributed by a module, theme, or installation profile, and to revert, delete, or import configuration.&lt;/p&gt;
&lt;p&gt;This module doesn&amp;#39;t sufficiently protect the Import operation, thereby exposing a Cross Site Request Forgery (CSRF) vulnerability which can be exploited by unprivileged users to trick an administrator into unwanted import of configuration.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only configuration items distributed with a module, theme, or installation profile that is currently installed and enabled on the site can be imported, not arbitrary configuration values.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/config_update&lt;/p&gt;
&lt;p&gt;The Configuration Update Reports sub-module in the Configuration Update module project enables you to run reports to see what configuration on your site differs from the configuration distributed by a module, theme, or installation profile, and to revert, delete, or import configuration.&lt;/p&gt;
&lt;p&gt;This module doesn&amp;#39;t sufficiently protect the Import operation, thereby exposing a Cross Site Request Forgery (CSRF) vulnerability which can be exploited by unprivileged users to trick an administrator into unwanted import of configuration.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only configuration items distributed with a module, theme, or installation profile that is currently installed and enabled on the site can be imported, not arbitrary configuration values.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2017-091</guid>
      <pubDate>Wed, 06 Dec 2017 18:44:03 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2017-094</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2017-094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/link_click_count&lt;/p&gt;
&lt;p&gt;The Link Click Count module helps you to monitor the traffic to your website by creating link fields. These link fields can be individual links or internal/external links that can be added to the content type.&lt;/p&gt;
&lt;p&gt;The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. The security team takes action in cases like this without regard to the severity of the security issue in question. If you would like to maintain this module, please read: &amp;lt;https://www.drupal.org/node/251466&amp;gt;&lt;/p&gt;
&lt;p&gt;All projects that are being marked unsupported are given a score of critical. Code that is no longer maintained poses a threat to securing sites.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/link_click_count&lt;/p&gt;
&lt;p&gt;The Link Click Count module helps you to monitor the traffic to your website by creating link fields. These link fields can be individual links or internal/external links that can be added to the content type.&lt;/p&gt;
&lt;p&gt;The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. The security team takes action in cases like this without regard to the severity of the security issue in question. If you would like to maintain this module, please read: &amp;lt;https://www.drupal.org/node/251466&amp;gt;&lt;/p&gt;
&lt;p&gt;All projects that are being marked unsupported are given a score of critical. Code that is no longer maintained poses a threat to securing sites.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2017-094</guid>
      <pubDate>Wed, 20 Dec 2017 14:12:47 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2018-001</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-001</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/stacks&lt;/p&gt;
&lt;p&gt;This module enables content editors to create complex pages and layouts on the fly without the help from a developer, using reusable widgets.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently filter values posted to its AJAX endpoint, which leads to the instantiation of an arbitrary PHP class.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only sites with the Stacks - Content Feed submodule enabled are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/stacks&lt;/p&gt;
&lt;p&gt;This module enables content editors to create complex pages and layouts on the fly without the help from a developer, using reusable widgets.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently filter values posted to its AJAX endpoint, which leads to the instantiation of an arbitrary PHP class.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only sites with the Stacks - Content Feed submodule enabled are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2018-001</guid>
      <pubDate>Wed, 10 Jan 2018 17:57:53 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2018-002</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-002</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/node_view_permissions&lt;/p&gt;
&lt;p&gt;The Node view permissions module enables the &amp;#34;View own content&amp;#34; and &amp;#34;View any content&amp;#34; permissions for each content type on the permissions page.&lt;/p&gt;
&lt;p&gt;This module has a vulnerability that allows users with these permissions to view unpublished content that they are not otherwise authorized to view.&lt;/p&gt;
&lt;p&gt;**This issue was fixed by the maintainer outside of the normal security team protocols. Some issues were patched in 2014 for the 7.x version of this module. The 8.x release was updated within the last 6 months. Both are now flagged as security updates.**&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/node_view_permissions&lt;/p&gt;
&lt;p&gt;The Node view permissions module enables the &amp;#34;View own content&amp;#34; and &amp;#34;View any content&amp;#34; permissions for each content type on the permissions page.&lt;/p&gt;
&lt;p&gt;This module has a vulnerability that allows users with these permissions to view unpublished content that they are not otherwise authorized to view.&lt;/p&gt;
&lt;p&gt;**This issue was fixed by the maintainer outside of the normal security team protocols. Some issues were patched in 2014 for the 7.x version of this module. The 8.x release was updated within the last 6 months. Both are now flagged as security updates.**&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2018-002</guid>
      <pubDate>Wed, 10 Jan 2018 18:02:19 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2018-008</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-008</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/entity_ref_tab_formatter&lt;/p&gt;
&lt;p&gt;This module enables you to show referenced entities in tabs.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently sanitize the body fields of the referenced entities when it prints them to the tabs.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission create/edit content of the content type that is referenced.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/entity_ref_tab_formatter&lt;/p&gt;
&lt;p&gt;This module enables you to show referenced entities in tabs.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently sanitize the body fields of the referenced entities when it prints them to the tabs.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission create/edit content of the content type that is referenced.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2018-008</guid>
      <pubDate>Wed, 07 Feb 2018 18:45:12 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2018-014</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-014</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ckeditor_uploadimage&lt;/p&gt;
&lt;p&gt;This module enables you to drag and drop or paste images into CKEditor.  
The module does not sufficiently verify users permissions, which leads to anonymous users being able to upload files to the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ckeditor_uploadimage&lt;/p&gt;
&lt;p&gt;This module enables you to drag and drop or paste images into CKEditor.  
The module does not sufficiently verify users permissions, which leads to anonymous users being able to upload files to the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2018-014</guid>
      <pubDate>Wed, 21 Feb 2018 19:04:59 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2018-015</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-015</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/jsonapi&lt;/p&gt;
&lt;p&gt;This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.&lt;/p&gt;
&lt;p&gt;* The module doesn&amp;#39;t sufficiently associate cacheability metadata in certain situations thereby causing an access bypass vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker cannot trigger an exploitable situation themselves.
* The module doesn&amp;#39;t sufficiently check access in certain situations.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have permission to create entities of certain content entity types.&lt;/p&gt;
&lt;p&gt;#### Update: This is fixed in 8.x-1.10 not 8.x-1.9&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/jsonapi&lt;/p&gt;
&lt;p&gt;This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.&lt;/p&gt;
&lt;p&gt;* The module doesn&amp;#39;t sufficiently associate cacheability metadata in certain situations thereby causing an access bypass vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker cannot trigger an exploitable situation themselves.
* The module doesn&amp;#39;t sufficiently check access in certain situations.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have permission to create entities of certain content entity types.&lt;/p&gt;
&lt;p&gt;#### Update: This is fixed in 8.x-1.10 not 8.x-1.9&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2018-015</guid>
      <pubDate>Wed, 21 Feb 2018 20:12:22 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2018-016</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2018-016</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/jsonapi&lt;/p&gt;
&lt;p&gt;This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access when viewing related resources or relationships, thereby causing an access bypass vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must be allowed to view the related data, otherwise all they can glean is an entity type UUID and a UUID, which are meaningless by themselves.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/jsonapi&lt;/p&gt;
&lt;p&gt;This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check access when viewing related resources or relationships, thereby causing an access bypass vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must be allowed to view the related data, otherwise all they can glean is an entity type UUID and a UUID, which are meaningless by themselves.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2018-016</guid>
      <pubDate>Wed, 21 Mar 2018 16:59:32 +0000</pubDate>
    </item>
  </channel>
</rss>
