<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from drupal</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:49:17 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2023-030</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-030</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tfa&lt;/p&gt;
&lt;p&gt;This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently ensure all core login routes, including the password reset page, require a second factor credential.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tfa&lt;/p&gt;
&lt;p&gt;This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently ensure all core login routes, including the password reset page, require a second factor credential.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-030</guid>
      <pubDate>Wed, 12 Jul 2023 18:19:42 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-032</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-032</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/minifyhtml&lt;/p&gt;
&lt;p&gt;Carefully crafted input by an attacker will not be sanitized by this module, which can result in a script injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/minifyhtml&lt;/p&gt;
&lt;p&gt;Carefully crafted input by an attacker will not be sanitized by this module, which can result in a script injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-032</guid>
      <pubDate>Wed, 26 Jul 2023 19:19:38 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-031</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-031</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/symfony_mailer&lt;/p&gt;
&lt;p&gt;The module doesn’t sufficiently protect against malicious links, which means an attacker can trick an administrator into performing unwanted actions.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that the set of unwanted actions is limited to specific configurations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/symfony_mailer&lt;/p&gt;
&lt;p&gt;The module doesn’t sufficiently protect against malicious links, which means an attacker can trick an administrator into performing unwanted actions.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that the set of unwanted actions is limited to specific configurations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-031</guid>
      <pubDate>Wed, 26 Jul 2023 19:15:46 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-028</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-028</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/expandable_formatter&lt;/p&gt;
&lt;p&gt;This module enables you to render a field in an expandable/collapsible region.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently sanitize the field content when displaying it to an end user.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role capable of creating content that uses the field formatter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/expandable_formatter&lt;/p&gt;
&lt;p&gt;This module enables you to render a field in an expandable/collapsible region.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently sanitize the field content when displaying it to an end user.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role capable of creating content that uses the field formatter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-028</guid>
      <pubDate>Wed, 28 Jun 2023 17:21:37 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-027</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-027</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/libraries_ui&lt;/p&gt;
&lt;p&gt;This module enables a UI to display all libraries provided by modules and themes on the Drupal site.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently protect the libraries reporting page. It curently is using the &amp;#39;access content&amp;#39; permission and not a proper administrative/access permission.&lt;/p&gt;
&lt;p&gt;The vulnerability/library information can be exploited by simply visiting/knowing the url of the reporting page. The solution is to protect the page via a module specific permission that must be granted by an administrative user.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/libraries_ui&lt;/p&gt;
&lt;p&gt;This module enables a UI to display all libraries provided by modules and themes on the Drupal site.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently protect the libraries reporting page. It curently is using the &amp;#39;access content&amp;#39; permission and not a proper administrative/access permission.&lt;/p&gt;
&lt;p&gt;The vulnerability/library information can be exploited by simply visiting/knowing the url of the reporting page. The solution is to protect the page via a module specific permission that must be granted by an administrative user.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-027</guid>
      <pubDate>Wed, 28 Jun 2023 17:15:03 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-029</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tacjs&lt;/p&gt;
&lt;p&gt;This module enables sites to comply with the European cookie law using tarteaucitron.js.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission &amp;#34;administer tacjs&amp;#34; regardless of other configurations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tacjs&lt;/p&gt;
&lt;p&gt;This module enables sites to comply with the European cookie law using tarteaucitron.js.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission &amp;#34;administer tacjs&amp;#34; regardless of other configurations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-029</guid>
      <pubDate>Wed, 28 Jun 2023 17:34:47 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-033</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-033</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/matomo&lt;/p&gt;
&lt;p&gt;This module enables you to add the Matomo web statistics tracking system to your website.&lt;/p&gt;
&lt;p&gt;The module does not check the Matomo JS code loaded on the website. So a user could configure the module to load JS from a malicious website.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission &amp;#34;administer matomo&amp;#34; or &amp;#34;administer matomo tag manager&amp;#34; (D8+ only) to access the settings forms where this can be configured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/matomo&lt;/p&gt;
&lt;p&gt;This module enables you to add the Matomo web statistics tracking system to your website.&lt;/p&gt;
&lt;p&gt;The module does not check the Matomo JS code loaded on the website. So a user could configure the module to load JS from a malicious website.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permission &amp;#34;administer matomo&amp;#34; or &amp;#34;administer matomo tag manager&amp;#34; (D8+ only) to access the settings forms where this can be configured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-033</guid>
      <pubDate>Wed, 02 Aug 2023 18:59:27 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-024</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-024</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/gridstack&lt;/p&gt;
&lt;p&gt;This module enables you to create dynamic layouts and add sample color palettes for color selection hints via its UI.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently sanitize the module&amp;#39;s settings in certain scenarios leading to a Cross Site Scripting vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permissions &amp;#34;administer gridstack&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/gridstack&lt;/p&gt;
&lt;p&gt;This module enables you to create dynamic layouts and add sample color palettes for color selection hints via its UI.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently sanitize the module&amp;#39;s settings in certain scenarios leading to a Cross Site Scripting vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role with the permissions &amp;#34;administer gridstack&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-024</guid>
      <pubDate>Wed, 28 Jun 2023 17:03:36 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-026</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-026</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/search_autocomplete&lt;/p&gt;
&lt;p&gt;This module enables you to use complex autocompletion in forms.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter text in the data it exposes, allowing a malicious user to enter specially crafted tags to exploit a Cross Site Scripting (XSS) attack.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role which allows them to publish the kind of data used in the autocomplete (for instance create nodes if the tool is used to search nodes, comments if the tool is used to search comments, etc...)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/search_autocomplete&lt;/p&gt;
&lt;p&gt;This module enables you to use complex autocompletion in forms.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter text in the data it exposes, allowing a malicious user to enter specially crafted tags to exploit a Cross Site Scripting (XSS) attack.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker must have a role which allows them to publish the kind of data used in the autocomplete (for instance create nodes if the tool is used to search nodes, comments if the tool is used to search comments, etc...)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-026</guid>
      <pubDate>Wed, 28 Jun 2023 17:11:07 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2023-023</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2023-023</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/gdpr_alert&lt;/p&gt;
&lt;p&gt;This module enables you to define configurable GDPR alert messages.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission &amp;#34;administer gdpr alert&amp;#34; regardless of other configurations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/gdpr_alert&lt;/p&gt;
&lt;p&gt;This module enables you to define configurable GDPR alert messages.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission &amp;#34;administer gdpr alert&amp;#34; regardless of other configurations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2023-023</guid>
      <pubDate>Wed, 28 Jun 2023 17:02:13 +0000</pubDate>
    </item>
  </channel>
</rss>
