<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from drupal</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:49:52 +0000</lastBuildDate>
    <item>
      <title>DRUPAL-CONTRIB-2026-172</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-172</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/webform&lt;/p&gt;
&lt;p&gt;The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Form submissions may include uploaded files.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently force certain uploaded file types to download when served. Under certain site configurations, a file uploaded through a webform could be rendered inline by a browser, resulting in a cross-site scripting vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that a user with permission to create or edit webforms must configure the form to allow the affected file extensions, and a user must specifically open the uploaded file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/webform&lt;/p&gt;
&lt;p&gt;The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Form submissions may include uploaded files.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently force certain uploaded file types to download when served. Under certain site configurations, a file uploaded through a webform could be rendered inline by a browser, resulting in a cross-site scripting vulnerability.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that a user with permission to create or edit webforms must configure the form to allow the affected file extensions, and a user must specifically open the uploaded file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-172</guid>
      <pubDate>Wed, 23 Sep 2026 16:26:49 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-191</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/diba_carousel&lt;/p&gt;
&lt;p&gt;The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration.&lt;/p&gt;
&lt;p&gt;When the &amp;#34;Allow HTML description&amp;#34; option is enabled, slide descriptions are rendered using the raw stored field value instead of the field&amp;#39;s rendered output. This bypasses Drupal&amp;#39;s text format filtering and output sanitization mechanisms.&lt;/p&gt;
&lt;p&gt;This vulnerability affects sites that use a formatted text field as the carousel description source and have enabled the &amp;#34;Allow HTML description&amp;#34; option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/diba_carousel&lt;/p&gt;
&lt;p&gt;The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration.&lt;/p&gt;
&lt;p&gt;When the &amp;#34;Allow HTML description&amp;#34; option is enabled, slide descriptions are rendered using the raw stored field value instead of the field&amp;#39;s rendered output. This bypasses Drupal&amp;#39;s text format filtering and output sanitization mechanisms.&lt;/p&gt;
&lt;p&gt;This vulnerability affects sites that use a formatted text field as the carousel description source and have enabled the &amp;#34;Allow HTML description&amp;#34; option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-191</guid>
      <pubDate>Wed, 23 Sep 2026 17:24:33 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-187</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-187</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ai_ckeditor&lt;/p&gt;
&lt;p&gt;This module enables you to use AI to fill in or replace text in CKEditor.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/ai_ckeditor&lt;/p&gt;
&lt;p&gt;This module enables you to use AI to fill in or replace text in CKEditor.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-187</guid>
      <pubDate>Wed, 23 Sep 2026 17:20:32 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-188</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-188</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/combined_image_style&lt;/p&gt;
&lt;p&gt;This module enables you to combine multiple image styles into a single image derivative.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.&lt;/p&gt;
&lt;p&gt;Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core&amp;#39;s token check.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/combined_image_style&lt;/p&gt;
&lt;p&gt;This module enables you to combine multiple image styles into a single image derivative.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.&lt;/p&gt;
&lt;p&gt;Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core&amp;#39;s token check.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-188</guid>
      <pubDate>Wed, 23 Sep 2026 17:21:51 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-189</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-189</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/css_usage_analyzer&lt;/p&gt;
&lt;p&gt;This module lets a frontend scanner post CSS-usage measurements to the site so admin reports can show real-page statistics.&lt;/p&gt;
&lt;p&gt;This module doesn&amp;#39;t sufficiently protect the `/css-usage-analyzer/save` endpoint against forged or repeated submissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/css_usage_analyzer&lt;/p&gt;
&lt;p&gt;This module lets a frontend scanner post CSS-usage measurements to the site so admin reports can show real-page statistics.&lt;/p&gt;
&lt;p&gt;This module doesn&amp;#39;t sufficiently protect the `/css-usage-analyzer/save` endpoint against forged or repeated submissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-189</guid>
      <pubDate>Wed, 23 Sep 2026 17:22:38 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-190</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-190</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/smart_content&lt;/p&gt;
&lt;p&gt;This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.&lt;/p&gt;
&lt;p&gt;The Smart Content Block submodule doesn&amp;#39;t sufficiently check block access when it renders the blocks of a &amp;#34;Display Blocks&amp;#34; reaction through the module&amp;#39;s AJAX endpoint.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/smart_content&lt;/p&gt;
&lt;p&gt;This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.&lt;/p&gt;
&lt;p&gt;The Smart Content Block submodule doesn&amp;#39;t sufficiently check block access when it renders the blocks of a &amp;#34;Display Blocks&amp;#34; reaction through the module&amp;#39;s AJAX endpoint.&lt;/p&gt;
&lt;p&gt;This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-190</guid>
      <pubDate>Wed, 23 Sep 2026 17:23:37 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-186</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/webform_rest&lt;/p&gt;
&lt;p&gt;This module enables you to retrieve and submit webforms via REST.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/webform_rest&lt;/p&gt;
&lt;p&gt;This module enables you to retrieve and submit webforms via REST.&lt;/p&gt;
&lt;p&gt;The module doesn&amp;#39;t sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-186</guid>
      <pubDate>Wed, 23 Sep 2026 17:19:41 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-185</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-185</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/editoria11y&lt;/p&gt;
&lt;p&gt;This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.&lt;/p&gt;
&lt;p&gt;The module incorrectly described a permission as a &amp;#34;view&amp;#34; permission when it grants edit and delete access to module data, resulting in a potential access bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/editoria11y&lt;/p&gt;
&lt;p&gt;This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.&lt;/p&gt;
&lt;p&gt;The module incorrectly described a permission as a &amp;#34;view&amp;#34; permission when it grants edit and delete access to module data, resulting in a potential access bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-185</guid>
      <pubDate>Wed, 23 Sep 2026 17:18:31 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-184</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tawk_to&lt;/p&gt;
&lt;p&gt;This module provides integration of the tawk.to live chat for Drupal sites.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/tawk_to&lt;/p&gt;
&lt;p&gt;This module provides integration of the tawk.to live chat for Drupal sites.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-184</guid>
      <pubDate>Wed, 23 Sep 2026 17:14:48 +0000</pubDate>
    </item>
    <item>
      <title>DRUPAL-CONTRIB-2026-182</title>
      <link>https://cve.radiocsirt.org/vuln/drupal-contrib-2026-182</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/rest_api_authentication&lt;/p&gt;
&lt;p&gt;This module enables you to add an extra authentication layer to the API.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist:https://packages.drupal.org/8: drupal/rest_api_authentication&lt;/p&gt;
&lt;p&gt;This module enables you to add an extra authentication layer to the API.&lt;/p&gt;
&lt;p&gt;The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/drupal-contrib-2026-182</guid>
      <pubDate>Wed, 23 Sep 2026 17:10:00 +0000</pubDate>
    </item>
  </channel>
</rss>
