Drupal
46 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-10768
CRITICAL 9.8
Localgov Workflows — Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects …
2026-07-10
CVE-2026-10769
MEDIUM 5.4
Commerce Core — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal C…
2026-07-10
CVE-2026-10770
MEDIUM 6.1
Anti Spam By Cleantalk — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A…
2026-07-10
CVE-2026-11908
MEDIUM 5.4
Tagify — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal T…
2026-07-10
CVE-2026-11909
LOW 3.3
Examples For Developers — Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue aff…
2026-07-10
CVE-2026-11913
CRITICAL 9.8
Mother May I — vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
2026-07-10
CVE-2026-11914
MEDIUM 5.9
Composer — vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
2026-07-10
CVE-2026-11915
MEDIUM 5.9
Brute Force Attack Protection — vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protectio…
2026-07-10
CVE-2026-12535
CRITICAL 9.8
Formatter Field — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatt…
2026-07-10
CVE-2026-13231
MEDIUM 6.1
Advanced Content Feedback (Aka Admin Feedback) — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A…
2026-07-10
CVE-2026-13232
LOW 3.1
Advanced Content Feedback (Aka Admin Feedback) — Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful…
2026-07-10
CVE-2026-13233
LOW 3.3
Openai Provider — Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery.…
2026-07-10
CVE-2026-13234
MEDIUM 6.1
Ai (Artificial Intelligence) — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A…
2026-07-10
CVE-2026-13235
LOW 3.3
Ai (Artificial Intelligence) — Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issu…
2026-07-10
CVE-2026-13236
MEDIUM 4.2
Ai Agents — Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents…
2026-07-10
CVE-2026-13237
MEDIUM 4.8
Ai Agents — Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agen…
2026-07-10
CVE-2026-13238
MEDIUM 4.8
Commerce Realex / Global Payments — Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. Th…
2026-07-10
CVE-2026-13239
MEDIUM 6.5
Wisski — Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versi…
2026-07-10
CVE-2026-13240
MEDIUM 6.5
Paragraphs — Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragrap…
2026-07-10
CVE-2026-13241
MEDIUM 6.5
Paragraphs — Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragrap…
2026-07-10
CVE-2026-13242
MEDIUM 6.5
Geolocation Field — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal G…
2026-07-10
CVE-2026-13243
MEDIUM 4.8
Salesforce Suite — Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. …
2026-07-10
CVE-2026-13244
HIGH 8.1
Tealium Iq Tag Management — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium…
2026-07-10
CVE-2026-15079
MEDIUM 5.4
Login Disable — Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute F…
2026-07-10
CVE-2026-15080
MEDIUM 4.3
Ray Enterprise Translation — Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request…
2026-07-10
CVE-2026-15081
HIGH 7.4
Location Selector — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal L…
2026-07-10
CVE-2026-15082
MEDIUM 5.4
Siteimprove Analytics — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal S…
2026-07-10
CVE-2026-15083
MEDIUM 4.2
Eca: Event Condition Action — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Ev…
2026-07-10
CVE-2026-15084
MEDIUM 5.4
Ui Patterns (Sdc In Drupal Ui) — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal U…
2026-07-10
CVE-2026-15085
MEDIUM 5.4
Ai Seo/Geo Analyzer — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A…
2026-07-10
CVE-2026-15086
MEDIUM 5.9
Raw Formatter [Meta Tag Formatter] — vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag…
2026-07-10
CVE-2026-15087
MEDIUM 5.9
Clean Restful — vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
2026-07-10
CVE-2026-15089
CRITICAL 9.1
Commerce Guest Registration — vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration ve…
2026-07-10
CVE-2026-55803
MEDIUM 5.9
Drupal Core — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal …
2026-07-10
CVE-2026-55804
MEDIUM 5.9
Drupal Core — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal …
2026-07-10
CVE-2026-55806
MEDIUM 5.9
Drupal Core — URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofin…
2026-07-10
CVE-2026-55807
LOW 3.1
Drupal Core — Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. Thi…
2026-07-10
CVE-2026-55808
MEDIUM 5.4
Drupal Core — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal D…
2026-07-10
CVE-2026-55809
HIGH 8.1
Flag Attendance Field — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag at…
2026-07-10
CVE-2026-55810
HIGH 8.1
Plotly.Js Graphing — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.…
2026-07-10
CVE-2026-58587
MEDIUM 6.1
Drupal Canvas — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal D…
2026-07-10
CVE-2026-58588
MEDIUM 6.1
Drupal Canvas — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal D…
2026-07-10
CVE-2026-58589
MEDIUM 5.4
Flowdrop — Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop v…
2026-07-10
CVE-2026-58590
MEDIUM 5.4
Flowdrop — Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop v…
2026-07-10
CVE-2026-58591
MEDIUM 5.4
Colorbox — Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal C…
2026-07-10
CVE-2026-9726
CRITICAL 9.8
Drupal Alternativecommerce (Basket) — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal …
2026-07-10