<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Drupal</title>
  <link>https://cvedaily.com/pages/tags/drupal.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/drupal.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Drupal</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-6816 – An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6816</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6816</strong></p>
  <p>An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users.   This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5343 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5343</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5343</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.  This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4929 – Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4929</guid>
    <pubDate>Thu, 21 May 2026 22:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4929</strong></p>
  <p>Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context. This affects versions from 7.x-…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4093 – In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4093</guid>
    <pubDate>Thu, 21 May 2026 22:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4093</strong></p>
  <p>In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline.  Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/J…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9082 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9082</guid>
    <pubDate>Wed, 20 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9082</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.  This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8495 – Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8495</guid>
    <pubDate>Tue, 19 May 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8495</strong></p>
  <p>Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.  This issue affects Date iCal: from 0.0.0 before 4.0.15.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8493 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8493</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8493</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS).  This issue affects Colorbox Inline: from 0.0.0 before 2.1.1.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8492 – Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8492</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8492</strong></p>
  <p>Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing.  This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-471</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8491 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Nod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8491</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8491</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.  This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6871 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6871</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6871</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS).  This issue affects Obfuscate: from 0.0.0 before 2.0.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6367 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6367</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6367</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).  This issue affects Drupal core: from 11.3.0 before 11.3.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6366 – Improperly Controlled Modification of Dynamically-Determined Object Attributes v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6366</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6366</strong></p>
  <p>Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.  This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6365 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6365</guid>
    <pubDate>Tue, 19 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6365</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).  This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6095 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6095</guid>
    <pubDate>Tue, 19 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6095</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime allows Cross-Site Scripting (XSS).  This issue affects Orejime: from 0.0.0 before 2.0.16.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50957 – Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50957</guid>
    <pubDate>Sun, 10 May 2026 13:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50957</strong></p>
  <p>Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary JavaScript in victim browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1556 – Information disclosure in the file URI processing of File (Field) Paths in Drupa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1556</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1556</strong></p>
  <p>Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenticated users to disclose other users’ private files via filename‑collision uploads. This can cause hook_node_insert() consumers (for example, email attachment modules) to receive the wrong file URI, bypassing normal access controls on private files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0748 – In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0748</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0748</strong></p>
  <p>In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls and discloses unpublished node titles and IDs.   Exploit affects versions 7.x-1.0 up to and including…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4933 – Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4933</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4933</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4393 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4393</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4393</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue affects Automated Logout: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.2.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3573 – Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3573</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3573</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.1.11, from 1.2.0 before 1.2.12.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3532 – Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3532</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3532</strong></p>
  <p>Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3531 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3531</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3531</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3530 – Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3530</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3530</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3529 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3529</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3529</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics GA4 allows Cross-Site Scripting (XSS).This issue affects Google Analytics GA4: from 0.0.0 before 1.1.14.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3528 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3528</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3528</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scripting (XSS).This issue affects Calculation Fields: from 0.0.0 before 1.0.4.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3527 – Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashbo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3527</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3527</strong></p>
  <p>Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AJAX Dashboard: from 0.0.0 before 3.1.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3526 – Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3526</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3526</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3525 – Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3525</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3525</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3218 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3218</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3218</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3217 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3217</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3217</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3216 – Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3216</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3216</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3215 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3215</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3215</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora allows Cross-Site Scripting (XSS).This issue affects Islandora: from 0.0.0 before 2.17.5.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3214 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3214</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3214</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3213 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3213</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3213</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Cross-Site Scripting (XSS).This issue affects Anti-Spam by CleanTalk: from 0.0.0 before 9.7.0.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3212 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3212</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3212</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.49.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3211 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3211</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3211</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.This issue affects Theme Negotiation by Rules: from 0.0.0 before 1.2.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3210 – Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3210</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3210</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2349 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2349</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2349</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons allows Cross-Site Scripting (XSS).This issue affects UI Icons: from 0.0.0 before 1.0.1, from 1.1.0 before 1.1.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2348 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2348</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2348</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1917 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1917</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1917</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1554 – XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1554</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1554</strong></p>
  <p>XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1553 – Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Br...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1553</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1553</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0948 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0948</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0948</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO Login: from 0.0.0 before 1.0.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0947 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0947</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0947</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0946 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0946</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0946</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0945 – Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0945</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0945</strong></p>
  <p>Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before 1.5.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0944 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Gro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0944</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0944</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This issue affects Group invite: from 0.0.0 before 2.3.9, from 3.0.0 before 3.0.4, from 4.0.0 before 4.0.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14840 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14840</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14840</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14472 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14472</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14472</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from 3.7.0 before 3.7.3.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13986 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13986</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13986</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13985 – Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Bro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13985</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13985</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13984 – Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13984</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13984</strong></p>
  <p>Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13983 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13983</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13983</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.44.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13982 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13982</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13982</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Restriction: from 0.0.0 before 1.0.3.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13981 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13981</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13981</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS).This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.7, from 1.1.0 before 1.1.7, from 1.2.0 before 1.2.4.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13980 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13980</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13980</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Features: from 0.0.0 before 1.2.10, from 1.3.0 before 1.3.6, from 1.4.0 before 1.4.3, from 1.5.0 before 1.5.1, from 1.6.0 before 1.6.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13979 – Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13979</guid>
    <pubDate>Wed, 28 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13979</strong></p>
  <p>Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0750 – Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0750</guid>
    <pubDate>Wed, 28 Jan 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0750</strong></p>
  <p>Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication Bypass.This issue affects Drupal Commerce Paybox: from 7-x-1.0 through 7.X-1.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0749 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0749</guid>
    <pubDate>Wed, 28 Jan 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0749</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14557 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14557</guid>
    <pubDate>Wed, 14 Jan 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14557</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Facebook Pixel facebook_pixel allows Stored XSS.This issue affects Facebook Pixel: from 7.X-1.0 through 7.X-1.1.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14556 – Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14556</guid>
    <pubDate>Wed, 14 Jan 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14556</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag allows Cross-Site Scripting (XSS).This issue affects Flag: from 7.X-3.0 through 7.X-3.9.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12848 – Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12848</guid>
    <pubDate>Wed, 26 Nov 2025 02:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12848</strong></p>
  <p>Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this vulnerability by uploading a file with a malicious filename containing JavaScript code (e.g., "<img src=1 onerror=alert(document.domain)>") to a Webform node with a Multifile field where file type validation is disabled. Thi…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-13083 – Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13083</guid>
    <pubDate>Tue, 18 Nov 2025 17:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-13083</strong></p>
  <p>Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-525</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13082 – User Interface (UI) Misrepresentation of Critical Information vulnerability in D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13082</guid>
    <pubDate>Tue, 18 Nov 2025 17:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13082</strong></p>
  <p>User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13081 – Improperly Controlled Modification of Dynamically-Determined Object Attributes v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13081</guid>
    <pubDate>Tue, 18 Nov 2025 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13081</strong></p>
  <p>Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13080 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Dru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13080</guid>
    <pubDate>Tue, 18 Nov 2025 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13080</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-12761 – Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12761</guid>
    <pubDate>Tue, 18 Nov 2025 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-12761</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Site Scripting (XSS).This issue affects Simple multi step form: from 0.0.0 before 2.0.0.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12760 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12760</guid>
    <pubDate>Tue, 18 Nov 2025 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12760</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9954 – Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9954</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9954</strong></p>
  <p>Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12466 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12466</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12466</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass.This issue affects Simple OAuth (OAuth2) & OpenID Connect: from 6.0.0 before 6.0.7.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12083 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12083</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12083</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme Design System allows Cross-Site Scripting (XSS).This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12082 – Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12082</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12082</strong></p>
  <p>Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-10931 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10931</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-10931</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS).This issue affects Umami Analytics: from 0.0.0 before 1.0.1.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10930 – Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10930</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10930</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10929 – Improper Validation of Consistency within Input vulnerability in Drupal Reverse ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10929</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10929</strong></p>
  <p>Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10928 – Improper Restriction of Excessive Authentication Attempts vulnerability in Drupa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10928</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10928</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10927 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10927</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10927</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS).This issue affects Plausible tracking: from 0.0.0 before 1.0.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10926 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10926</guid>
    <pubDate>Thu, 30 Oct 2025 00:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10926</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field allows Cross-Site Scripting (XSS).This issue affects JSON Field: from 0.0.0 before 1.5.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9554 – Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9554</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9554</strong></p>
  <p>Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9553 – Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9553</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9553</strong></p>
  <p>Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9552 – Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9552</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9552</strong></p>
  <p>Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9551 – Improper Restriction of Excessive Authentication Attempts vulnerability in Drupa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9551</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9551</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before 7.X-2.5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9550 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9550</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9550</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9549 – Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9549</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9549</strong></p>
  <p>Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8093 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8093</guid>
    <pubDate>Fri, 10 Oct 2025 23:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8093</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11570 – Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11570</guid>
    <pubDate>Fri, 10 Oct 2025 05:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11570</strong></p>
  <p>Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.**Note:**This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for thi…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8996 – Missing Authorization vulnerability in Drupal Layout Builder Advanced Permission...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8996</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8996</strong></p>
  <p>Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8995 – Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8995</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8995</strong></p>
  <p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8675 – Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8675</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8675</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from 0.0.0 before 1.0.6.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8362 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8362</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8362</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag Manager allows Cross-Site Scripting (XSS).This issue affects GoogleTag Manager: from 0.0.0 before 1.10.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8361 – Missing Authorization vulnerability in Drupal Config Pages allows Forceful Brows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8361</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8361</strong></p>
  <p>Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-962</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8092 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8092</guid>
    <pubDate>Fri, 15 Aug 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8092</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.16.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7717 – Missing Authorization vulnerability in Drupal File Download allows Forceful Brow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7717</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7717</strong></p>
  <p>Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from 2.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7716 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7716</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7716</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS).This issue affects Real-time SEO for Drupal: from 2.0.0 before 2.2.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7715 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7715</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7715</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attributes allows Cross-Site Scripting (XSS).This issue affects Block Attributes: from 0.0.0 before 1.1.0, from 2.0.0 before 2.0.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7393 – Improper Restriction of Excessive Authentication Attempts vulnerability in Drupa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7393</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7393</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7392 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7392</guid>
    <pubDate>Mon, 21 Jul 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7392</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Addons allows Cross-Site Scripting (XSS).This issue affects Cookies Addons: from 1.0.0 before 1.2.4.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48294 – Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48294</guid>
    <pubDate>Wed, 16 Jul 2025 11:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48294</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress fg-drupal-to-wp allows Server Side Request Forgery.This issue affects FG Drupal to WordPress: from n/a through <= 3.90.0.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7031 – Missing Authentication for Critical Function vulnerability in Drupal Config Page...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7031</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7031</strong></p>
  <p>Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from 0.0.0 before 1.0.4.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7030 – Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7030</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7030</strong></p>
  <p>Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7030">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
