← Browse

Drupal

46 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-10768 CRITICAL 9.8 Localgov Workflows — Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects … 2026-07-10 CVE-2026-10769 MEDIUM 5.4 Commerce Core — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal C… 2026-07-10 CVE-2026-10770 MEDIUM 6.1 Anti Spam By Cleantalk — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A… 2026-07-10 CVE-2026-11908 MEDIUM 5.4 Tagify — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal T… 2026-07-10 CVE-2026-11909 LOW 3.3 Examples For Developers — Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue aff… 2026-07-10 CVE-2026-11913 CRITICAL 9.8 Mother May I — vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. 2026-07-10 CVE-2026-11914 MEDIUM 5.9 Composer — vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. 2026-07-10 CVE-2026-11915 MEDIUM 5.9 Brute Force Attack Protection — vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protectio… 2026-07-10 CVE-2026-12535 CRITICAL 9.8 Formatter Field — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatt… 2026-07-10 CVE-2026-13231 MEDIUM 6.1 Advanced Content Feedback (Aka Admin Feedback) — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A… 2026-07-10 CVE-2026-13232 LOW 3.1 Advanced Content Feedback (Aka Admin Feedback) — Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful… 2026-07-10 CVE-2026-13233 LOW 3.3 Openai Provider — Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery.… 2026-07-10 CVE-2026-13234 MEDIUM 6.1 Ai (Artificial Intelligence) — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A… 2026-07-10 CVE-2026-13235 LOW 3.3 Ai (Artificial Intelligence) — Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issu… 2026-07-10 CVE-2026-13236 MEDIUM 4.2 Ai Agents — Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents… 2026-07-10 CVE-2026-13237 MEDIUM 4.8 Ai Agents — Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agen… 2026-07-10 CVE-2026-13238 MEDIUM 4.8 Commerce Realex / Global Payments — Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. Th… 2026-07-10 CVE-2026-13239 MEDIUM 6.5 Wisski — Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versi… 2026-07-10 CVE-2026-13240 MEDIUM 6.5 Paragraphs — Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragrap… 2026-07-10 CVE-2026-13241 MEDIUM 6.5 Paragraphs — Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragrap… 2026-07-10 CVE-2026-13242 MEDIUM 6.5 Geolocation Field — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal G… 2026-07-10 CVE-2026-13243 MEDIUM 4.8 Salesforce Suite — Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. … 2026-07-10 CVE-2026-13244 HIGH 8.1 Tealium Iq Tag Management — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium… 2026-07-10 CVE-2026-15079 MEDIUM 5.4 Login Disable — Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute F… 2026-07-10 CVE-2026-15080 MEDIUM 4.3 Ray Enterprise Translation — Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request… 2026-07-10 CVE-2026-15081 HIGH 7.4 Location Selector — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal L… 2026-07-10 CVE-2026-15082 MEDIUM 5.4 Siteimprove Analytics — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal S… 2026-07-10 CVE-2026-15083 MEDIUM 4.2 Eca: Event Condition Action — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Ev… 2026-07-10 CVE-2026-15084 MEDIUM 5.4 Ui Patterns (Sdc In Drupal Ui) — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal U… 2026-07-10 CVE-2026-15085 MEDIUM 5.4 Ai Seo/Geo Analyzer — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A… 2026-07-10 CVE-2026-15086 MEDIUM 5.9 Raw Formatter [Meta Tag Formatter] — vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag… 2026-07-10 CVE-2026-15087 MEDIUM 5.9 Clean Restful — vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. 2026-07-10 CVE-2026-15089 CRITICAL 9.1 Commerce Guest Registration — vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration ve… 2026-07-10 CVE-2026-55803 MEDIUM 5.9 Drupal Core — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal … 2026-07-10 CVE-2026-55804 MEDIUM 5.9 Drupal Core — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal … 2026-07-10 CVE-2026-55806 MEDIUM 5.9 Drupal Core — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofin… 2026-07-10 CVE-2026-55807 LOW 3.1 Drupal Core — Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. Thi… 2026-07-10 CVE-2026-55808 MEDIUM 5.4 Drupal Core — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal D… 2026-07-10 CVE-2026-55809 HIGH 8.1 Flag Attendance Field — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag at… 2026-07-10 CVE-2026-55810 HIGH 8.1 Plotly.Js Graphing — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.… 2026-07-10 CVE-2026-58587 MEDIUM 6.1 Drupal Canvas — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal D… 2026-07-10 CVE-2026-58588 MEDIUM 6.1 Drupal Canvas — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal D… 2026-07-10 CVE-2026-58589 MEDIUM 5.4 Flowdrop — Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop v… 2026-07-10 CVE-2026-58590 MEDIUM 5.4 Flowdrop — Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop v… 2026-07-10 CVE-2026-58591 MEDIUM 5.4 Colorbox — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal C… 2026-07-10 CVE-2026-9726 CRITICAL 9.8 Drupal Alternativecommerce (Basket) — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal … 2026-07-10