<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Drupal (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/drupal.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/drupal-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Drupal (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-5343 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5343</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5343</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.  This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9082 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9082</guid>
    <pubDate>Wed, 20 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9082</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.  This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8495 – Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8495</guid>
    <pubDate>Tue, 19 May 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8495</strong></p>
  <p>Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.  This issue affects Date iCal: from 0.0.0 before 4.0.15.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4933 – Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4933</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4933</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3573 – Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3573</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3573</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.1.11, from 1.2.0 before 1.2.12.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0945 – Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0945</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0945</strong></p>
  <p>Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14840 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14840</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14840</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14472 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14472</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14472</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from 3.7.0 before 3.7.3.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13982 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13982</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13982</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Restriction: from 0.0.0 before 1.0.3.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0750 – Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0750</guid>
    <pubDate>Wed, 28 Jan 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0750</strong></p>
  <p>Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9954 – Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9954</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9954</strong></p>
  <p>Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12466 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12466</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12466</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12082 – Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12082</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12082</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8093 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8093</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8093</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8995 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8995</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8995</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8675 – Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8675</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8675</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from 0.0.0 before 1.0.6.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8361 – Missing Authorization vulnerability in Drupal Config Pages allows Forceful Brows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8361</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8361</strong></p>
  <p>Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-962</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8092 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8092</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8092</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.16.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7717 – Missing Authorization vulnerability in Drupal File Download allows Forceful Brow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7717</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7717</strong></p>
  <p>Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from 2.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7393 – Improper Restriction of Excessive Authentication Attempts vulnerability in Drupa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7393</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7393</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48921 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48921</guid>
    <pubDate>Thu, 26 Jun 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48921</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.14, from 12.4.0 before 12.4.13.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48920 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48920</guid>
    <pubDate>Fri, 13 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48920</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48918 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48918</guid>
    <pubDate>Fri, 13 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48918</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48915 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48915</guid>
    <pubDate>Fri, 13 Jun 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48915</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48914 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48914</guid>
    <pubDate>Fri, 13 Jun 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48914</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48447 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48447</guid>
    <pubDate>Wed, 11 Jun 2025 15:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48447</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgallery allows Cross-Site Scripting (XSS).This issue affects Lightgallery: from 0.0.0 before 1.6.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48446 – Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48446</guid>
    <pubDate>Wed, 11 Jun 2025 15:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48446</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48445 – Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48445</guid>
    <pubDate>Wed, 11 Jun 2025 15:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48445</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from 0.0.0 before 2.1.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4416 – Allocation of Resources Without Limits or Throttling vulnerability in Drupal Eve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4416</guid>
    <pubDate>Wed, 21 May 2025 17:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4416</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, from 4.0.0 before 4.0.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47710 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47710</guid>
    <pubDate>Wed, 14 May 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47710</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47708 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47708</guid>
    <pubDate>Wed, 14 May 2025 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47708</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47707 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47707</guid>
    <pubDate>Wed, 14 May 2025 17:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47707</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47701 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47701</guid>
    <pubDate>Wed, 14 May 2025 17:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47701</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from 0.0.0 before 1.3.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3904 – Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3904</guid>
    <pubDate>Wed, 23 Apr 2025 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3904</strong></p>
  <p>Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3903 – Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3903</guid>
    <pubDate>Wed, 23 Apr 2025 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3903</strong></p>
  <p>Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31694 – Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31694</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31694</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31692 – Improper Neutralization of Special Elements used in an OS Command ('OS Command I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31692</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31692</strong></p>
  <p>Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31691 – Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Brow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31691</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31691</strong></p>
  <p>Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31690 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31690</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31690</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31689 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31689</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31689</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31686 – Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31686</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31686</strong></p>
  <p>Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31685 – Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31685</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31685</strong></p>
  <p>Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31681 – Missing Authorization vulnerability in Drupal Authenticator Login allows Forcefu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31681</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31681</strong></p>
  <p>Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31678 – Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31678</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31678</strong></p>
  <p>Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31677 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31677</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31677</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31676 – Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31676</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31676</strong></p>
  <p>Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31674 – Improperly Controlled Modification of Dynamically-Determined Object Attributes v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31674</guid>
    <pubDate>Mon, 31 Mar 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31674</strong></p>
  <p>Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13311 – Vulnerability in Drupal Allow All File Extensions for file fields.This issue aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13311</guid>
    <pubDate>Thu, 09 Jan 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13311</strong></p>
  <p>Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13291 – Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13291</guid>
    <pubDate>Thu, 09 Jan 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13291</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13285 – Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13285</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13285</strong></p>
  <p>Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13284 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13284</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13284</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13282 – Incorrect Authorization vulnerability in Drupal Block permissions allows Forcefu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13282</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13282</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13281 – Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Br...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13281</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13281</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13280 – Insufficient Session Expiration vulnerability in Drupal Persistent Login allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13280</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13280</strong></p>
  <p>Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13279 – Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13279</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13279</strong></p>
  <p>Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13278 – Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13278</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13278</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13277 – Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Bro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13277</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13277</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13276 – Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13276</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13276</strong></p>
  <p>Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13267 – Improper Neutralization of Directives in Statically Saved Code ('Static Code Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13267</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13267</strong></p>
  <p>Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-96</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13265 – Improper Neutralization of Directives in Statically Saved Code ('Static Code Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13265</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13265</strong></p>
  <p>Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-96</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13264 – Improper Neutralization of Directives in Statically Saved Code ('Static Code Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13264</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13264</strong></p>
  <p>Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-96</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13260 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13260</guid>
    <pubDate>Thu, 09 Jan 2025 20:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13260</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13259 – Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13259</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13259</strong></p>
  <p>Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13258 – Incorrect Authorization vulnerability in Drupal Drupal REST &amp; JSON API Authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13258</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13258</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13256 – Insufficient Granularity of Access Control vulnerability in Drupal Email Contact...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13256</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13256</strong></p>
  <p>Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13255 – Exposure of Sensitive Information Through Data Queries vulnerability in Drupal R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13255</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13255</strong></p>
  <p>Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-202</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13254 – Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13254</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13254</strong></p>
  <p>Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13253 – Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notificati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13253</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13253</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13251 – Incorrect Privilege Assignment vulnerability in Drupal Registration role allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13251</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13251</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13250 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13250</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13250</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13244 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13244</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13244</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13242 – Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13242</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13242</strong></p>
  <p>Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13241 – Improper Authorization vulnerability in Drupal Open Social allows Collect Data f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13241</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13241</strong></p>
  <p>Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13240 – Improper Access Control vulnerability in Drupal Open Social allows Collect Data ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13240</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13240</strong></p>
  <p>Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-13239 – Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13239</guid>
    <pubDate>Thu, 09 Jan 2025 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-13239</strong></p>
  <p>Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55638 – Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55638</guid>
    <pubDate>Tue, 10 Dec 2024 00:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55638</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9.  Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55637 – Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55637</guid>
    <pubDate>Tue, 10 Dec 2024 00:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55637</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.  Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55636 – Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55636</guid>
    <pubDate>Tue, 10 Dec 2024 00:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55636</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.  Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so called gadget chain presents no direct threat, but is a vector…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55634 – A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Dr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55634</guid>
    <pubDate>Tue, 10 Dec 2024 00:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55634</strong></p>
  <p>A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11941 – A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Dr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11941</guid>
    <pubDate>Thu, 05 Dec 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11941</strong></p>
  <p>A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22362 – Drupal contains a vulnerability with improper handling of structural elements. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22362</guid>
    <pubDate>Tue, 16 Jan 2024 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22362</strong></p>
  <p>Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5256 – In certain scenarios, Drupal's JSON:API module will output error backtraces. Wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5256</guid>
    <pubDate>Thu, 28 Sep 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5256</strong></p>
  <p>In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.  This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API.  The core REST and contributed GraphQL modules are not…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25277 – Drupal core sanitizes filenames with dangerous extensions upon upload (reference...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25277</guid>
    <pubDate>Wed, 26 Apr 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25277</strong></p>
  <p>Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010). However, the protections for these two vulnerabilities previously did not work correctly together. As a result, if the site were configured to allow the upload of files…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25275 – In some situations, the Image module does not correctly check access to image fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25275</guid>
    <pubDate>Wed, 26 Apr 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25275</strong></p>
  <p>In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system. Access to a non-public file is checked only if it is stored in the "private" file system. However, some contributed modules provide additional file systems, or schemes, which may lead to this vulnerab…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25273 – Drupal core's form API has a vulnerability where certain contributed or custom m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25273</guid>
    <pubDate>Wed, 26 Apr 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25273</strong></p>
  <p>Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26493 – Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26493</guid>
    <pubDate>Fri, 03 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26493</strong></p>
  <p>Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating existing users and existing roles, including administrative users/roles. This vulner…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25271 – Drupal core's form API has a vulnerability where certain contributed or custom m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25271</guid>
    <pubDate>Wed, 16 Feb 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25271</strong></p>
  <p>Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13677 – Under some circumstances, the Drupal core JSON:API module does not properly rest...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13677</guid>
    <pubDate>Fri, 11 Feb 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13677</strong></p>
  <p>Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13675 – Drupal's JSON:API and REST/File modules allow file uploads through their HTTP AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13675</guid>
    <pubDate>Fri, 11 Feb 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13675</strong></p>
  <p>Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13670 – Information Disclosure vulnerability in file module of Drupal Core allows an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13670</guid>
    <pubDate>Fri, 11 Feb 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13670</strong></p>
  <p>Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13663 – Cross Site Request Forgery vulnerability in Drupal Core Form API does not proper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13663</guid>
    <pubDate>Fri, 11 Jun 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13663</strong></p>
  <p>Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13665 – Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13665</guid>
    <pubDate>Wed, 05 May 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13665</strong></p>
  <p>Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13664 – Arbitrary PHP code execution vulnerability in Drupal Core under certain circumst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13664</guid>
    <pubDate>Wed, 05 May 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13664</strong></p>
  <p>Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25012 – The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to vie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25012</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25012</strong></p>
  <p>The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25002 – uploader.php in the KCFinder integration project through 2018-06-01 for Drupal m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25002</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25002</strong></p>
  <p>uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-20001 – The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-20001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-20001</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-20001</strong></p>
  <p>The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-20001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20005 – The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20005</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20005</strong></p>
  <p>The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20004 – The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20004</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20004</strong></p>
  <p>The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20003 – The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20003</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20003</strong></p>
  <p>The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20002 – The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20002</guid>
    <pubDate>Fri, 01 Jan 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20002</strong></p>
  <p>The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20002">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
