Drupal
by WordPress
CVEs (21)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11913 | Cri | 0.64 | 9.8 | 0.01 | Jul 10, 2026 | vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. | ||
| CVE-2026-15089 | Cri | 0.59 | 9.1 | 0.00 | Jul 10, 2026 | Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*. | ||
| CVE-2026-10768 | Cri | 0.57 | 9.8 | 0.02 | Jul 10, 2026 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. | ||
| CVE-2026-16645 | Cri | 0.52 | 9.1 | 0.00 | Aug 25, 2026 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | ||
| CVE-2026-16644 | Cri | 0.52 | 9.1 | 0.00 | Aug 25, 2026 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | ||
| CVE-2026-15081 | Hig | 0.48 | 7.4 | 0.00 | Jul 10, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0. | ||
| CVE-2026-16640 | Med | 0.40 | 6.1 | 0.00 | Aug 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0. | ||
| CVE-2026-15087 | Med | 0.38 | 5.9 | 0.00 | Jul 10, 2026 | vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. | ||
| CVE-2026-15086 | Med | 0.38 | 5.9 | 0.00 | Jul 10, 2026 | vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. | ||
| CVE-2026-11915 | Med | 0.38 | 5.9 | 0.00 | Jul 10, 2026 | vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. | ||
| CVE-2026-11914 | Med | 0.38 | 5.9 | 0.00 | Jul 10, 2026 | vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. | ||
| CVE-2026-16646 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*. | ||
| CVE-2026-15088 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | ||
| CVE-2026-18260 | Med | 0.30 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*. | ||
| CVE-2026-49977 | Med | 0.28 | 4.3 | 0.00 | Jul 17, 2026 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucitron button or whether the cookie corresponds to a service… | ||
| CVE-2026-58591 | Med | 0.28 | 5.4 | 0.00 | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0. | ||
| CVE-2026-58589 | Med | 0.28 | 5.4 | 0.00 | Jul 10, 2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. | ||
| CVE-2026-15080 | Med | 0.21 | 4.3 | 0.00 | Jul 10, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4. | ||
| CVE-2026-15916 | Med | 0.20 | 4.2 | 0.00 | Aug 25, 2026 | Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | ||
| CVE-2026-11909 | Low | 0.14 | 3.3 | 0.00 | Jul 10, 2026 | Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. |
- risk 0.64cvss 9.8epss 0.01
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
- risk 0.59cvss 9.1epss 0.00
Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
- risk 0.57cvss 9.8epss 0.02
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
- risk 0.52cvss 9.1epss 0.00
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
- risk 0.52cvss 9.1epss 0.00
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
- risk 0.48cvss 7.4epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.
- risk 0.40cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.
- risk 0.38cvss 5.9epss 0.00
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
- risk 0.38cvss 5.9epss 0.00
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
- risk 0.38cvss 5.9epss 0.00
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
- risk 0.38cvss 5.9epss 0.00
vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
- risk 0.30cvss 5.7epss 0.00
Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.
- risk 0.28cvss 4.3epss 0.00
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucitron button or whether the cookie corresponds to a service…
- risk 0.28cvss 5.4epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.
- risk 0.28cvss 5.4epss 0.00
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.
- risk 0.20cvss 4.2epss 0.00
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
- risk 0.14cvss 3.3epss 0.00
Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
Page 1 of 2