vciy

CVEs we hold for Drupal

Records whose assigning authority named Drupal as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9726Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038Drupal AlternativeCommerce (Basket)
CVE-2026-9082Drupal core - Highly critical - SQL injection - SA-CORE-2026-004Drupal core
CVE-2026-8495Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037Drupal Date iCal
CVE-2026-8493Colorbox Inline - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-036Drupal Colorbox Inline
CVE-2026-8492Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035Drupal with GTranslate
CVE-2026-8491Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034Drupal Node View Permissions
CVE-2026-81269Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108Drupal Data field
CVE-2026-81205LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115Drupal LDAP / Active Directory Integration
CVE-2026-81201Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116Drupal Monster Menus
CVE-2026-81168CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105Drupal CAPTCHA Protected Page
CVE-2026-81167Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103Drupal Address Suggestion
CVE-2026-81166Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109Drupal Digital Signage Framework
CVE-2026-81165Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104Drupal Blazy
CVE-2026-81164Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114Drupal Entity PDF
CVE-2026-81162DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure -…Drupal
CVE-2026-81161Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107Drupal Content Moderation Notifications
CVE-2026-81160Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117Drupal Slick Carousel
CVE-2026-81159Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106Drupal Commerce CyberSource
CVE-2026-81158Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113Drupal Entity API
CVE-2026-76782Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102Drupal Screenshot
CVE-2026-76759Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102Drupal Screenshot
CVE-2026-76758Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101Drupal Link content parser
CVE-2026-76757Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100Drupal Gammu SMS Daemon
CVE-2026-76756Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100Drupal Gammu SMS Daemon
CVE-2026-76755Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100Drupal Gammu SMS Daemon
CVE-2026-73478Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096Drupal Diff
CVE-2026-73477Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099Drupal Quick Tabs
CVE-2026-73476External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098Drupal External Authentication
CVE-2026-73475Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095Drupal Commerce PayPal
CVE-2026-73474Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097Drupal Entity Share Websub
CVE-2026-6871Obfuscate - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-033Drupal Obfuscate
CVE-2026-6816TFA Basic Plugins - Access BypassDrupal TFA Basic Plugins
CVE-2026-6367Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003Drupal core
CVE-2026-6366Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002Drupal core
CVE-2026-6365Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001Drupal core
CVE-2026-6095Orejime - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-032Drupal Orejime
CVE-2026-58591Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069Drupal Colorbox
CVE-2026-58590FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068Drupal FlowDrop
CVE-2026-58589FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067Drupal FlowDrop
CVE-2026-58588Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066Drupal Canvas
CVE-2026-58587Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065Drupal Canvas
CVE-2026-55810Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050Drupal Plotly.js Graphing
CVE-2026-55809Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049Drupal Flag attendance field
CVE-2026-55808Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009Drupal core
CVE-2026-55807Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008Drupal core
CVE-2026-55806Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007Drupal core
CVE-2026-55805Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012Drupal core
CVE-2026-55804Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006Drupal core
CVE-2026-55803Drupal core - Critical - PHP object injection - SA-CORE-2026-005Drupal core
CVE-2026-5343SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-031Drupal SAML SSO - Service Provider
CVE-2026-4933Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-029Drupal Unpublished Node Permissions
CVE-2026-4929Simple Hierarchical Select (Drupal 7) XSS in term-derived outputDrupal Simple Hierarchical Select (shs)
CVE-2026-4393Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030Drupal Automated Logout
CVE-2026-4093Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)Drupal Term Reference Tree
CVE-2026-3573AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028Drupal AI (Artificial Intelligence)
CVE-2026-3532OpenID Connect / OAuth client - Less critical - Access bypass - SA-CONTRIB-2026-027Drupal OpenID Connect / OAuth client
CVE-2026-3531OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026Drupal OpenID Connect / OAuth client
CVE-2026-3530OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure -…Drupal OpenID Connect / OAuth client
CVE-2026-3529Google Analytics GA4 - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-024Drupal Google Analytics GA4
CVE-2026-3528Calculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023Drupal Calculation Fields
CVE-2026-3527AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022Drupal AJAX Dashboard
CVE-2026-3526File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-021Drupal File Access Fix (deprecated)
CVE-2026-3525File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020Drupal File Access Fix (deprecated)
CVE-2026-3218Responsive Favicons - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-019Drupal Responsive Favicons
CVE-2026-3217SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018Drupal SAML SSO - Service Provider
CVE-2026-3216Drupal Canvas - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-017Drupal Canvas
CVE-2026-3215Islandora - Moderately critical - Arbitrary file upload, Cross-site scripting - SA-CONTRIB-2026-016Drupal Islandora
CVE-2026-3214CAPTCHA - Moderately critical - Access bypass - SA-CONTRIB-2026-015Drupal CAPTCHA
CVE-2026-3213Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014Drupal Anti-Spam by CleanTalk
CVE-2026-3212Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013Drupal Tagify
CVE-2026-3211Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012Drupal Theme Negotiation by Rules
CVE-2026-3210Material Icons - Moderately critical - Access bypass - SA-CONTRIB-2026-011Drupal Material Icons
CVE-2026-2349UI Icons - Critical - Cross-site Scripting - SA-CONTRIB-2026-010Drupal UI Icons
CVE-2026-2348Quick Edit - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-009Drupal Quick Edit
CVE-2026-1917Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008Drupal Login Disable
CVE-2026-18986Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094Drupal Entity Browser
CVE-2026-18985Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093Drupal Edit in-place field
CVE-2026-18261Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092Drupal Powerful Surveys
CVE-2026-18260Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110Drupal Disable Login Page
CVE-2026-18259Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090Drupal Token Content Access
CVE-2026-16647Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111Drupal Disable Login Page
CVE-2026-16646PanKM - Critical - Unsupported - SA-CONTRIB-2026-083Drupal PanKM
CVE-2026-16645PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088Drupal PhotoSwipe - Responsive JavaScript Modal Image…
CVE-2026-16644Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087Drupal Webform REST
CVE-2026-16643Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086Drupal Lunr exposed filters
CVE-2026-16642Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085Drupal Email Login OTP
CVE-2026-16641Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084Drupal Commerce Elavon
CVE-2026-16640Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082Drupal Search API Autocomplete
CVE-2026-16639Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081Drupal Internationalization Single Sign-On
CVE-2026-16638Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080Drupal Media Folders
CVE-2026-15917Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011Drupal core
CVE-2026-15916Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010Drupal core
CVE-2026-1556Information disclosure via file URI overwrite in File (Field) PathsDrupal File (Field) Paths
CVE-2026-1554Central Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007Drupal Central Authentication System (CAS) Server
CVE-2026-1553Drupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006Drupal Canvas
CVE-2026-15089Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079Drupal Commerce guest registration
CVE-2026-15088Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089Drupal Development Environment
CVE-2026-15087Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078Drupal Clean RESTful
CVE-2026-15086Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077Drupal Raw Formatter [Meta Tag Formatter]
CVE-2026-15085AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076Drupal AI SEO/GEO Analyzer
CVE-2026-15084UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075Drupal UI)
CVE-2026-15083ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074Drupal ECA: Event - Condition - Action
CVE-2026-15082Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073Drupal Siteimprove Analytics
CVE-2026-15081Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072Drupal Location Selector
CVE-2026-15080Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071Drupal Ray Enterprise Translation
CVE-2026-15079Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070Drupal Login Disable
CVE-2026-13244Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064Drupal Tealium iQ Tag Management
CVE-2026-13243Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063Drupal Salesforce Suite
CVE-2026-13242Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062Drupal Geolocation Field
CVE-2026-13241Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061Drupal Paragraphs
CVE-2026-13240Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060Drupal Paragraphs
CVE-2026-13239WissKI - Critical - Access bypass - SA-CONTRIB-2026-059Drupal WissKI
CVE-2026-13238Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058Drupal Commerce Realex / Global Payments
CVE-2026-13237AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057Drupal AI Agents
CVE-2026-13236AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056Drupal AI Agents
CVE-2026-13235AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055Drupal AI (Artificial Intelligence)
CVE-2026-13234AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054Drupal AI (Artificial Intelligence)
CVE-2026-13233OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053Drupal OpenAI Provider
CVE-2026-13232Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference…Drupal Advanced Content Feedback (aka admin_feedback)
CVE-2026-13231Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051Drupal Advanced Content Feedback (aka admin_feedback)
CVE-2026-12535Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048Drupal Formatter Field
CVE-2026-11915Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047Drupal Brute force attack protection
CVE-2026-11914Composer - Critical - Unsupported - SA-CONTRIB-2026-046Drupal Composer
CVE-2026-11913Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045Drupal Mother May I
CVE-2026-11909Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044Drupal Examples for Developers
CVE-2026-11908Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043Drupal Tagify
CVE-2026-10770Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042Drupal Anti-Spam by CleanTalk
CVE-2026-10769Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041Drupal Commerce Core
CVE-2026-10768LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039Drupal LocalGov Workflows
CVE-2026-0948Microsoft Entra ID SSO Login - Critical - Access bypass - SA-CONTRIB-2026-005Drupal Microsoft Entra ID SSO Login
CVE-2026-0947AT Internet Piano Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-004Drupal AT Internet Piano Analytics
CVE-2026-0946AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003Drupal AT Internet SmartTag
CVE-2026-0945Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002Drupal Role Delegation
CVE-2026-0944Group invite - Moderately critical - Access bypass - SA-CONTRIB-2026-001Drupal Group invite
CVE-2026-0750Payment bypass in Commerce PayboxDrupal Commerce Paybox
CVE-2026-0749Cross-Site Scripting Vulnerability in Drupal Form Builder ModuleDrupal
CVE-2026-0748Access bypass in Drupal 7 i18n_node translation UIDrupal Internationalization (i18n) - i18n_node submodule
CVE-2025-9954Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105Drupal Acquia DAM
CVE-2025-9554Owl Carousel 2 - Critical - Unsupported - SA-CONTRIB-2025-104Drupal Owl Carousel 2
CVE-2025-9553API Key manager - Critical - Unsupported - SA-CONTRIB-2025-103Drupal API Key manager
CVE-2025-9552Synchronize composer.json With Contrib Modules - Critical - Unsupported - SA-CONTRIB-2025-102Drupal Synchronize composer.json With Contrib Modules
CVE-2025-9551Protected Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-101Drupal Protected Pages
CVE-2025-9550Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100Drupal Facets
CVE-2025-9549Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099Drupal Facets
CVE-2025-8996Layout Builder Advanced Permissions - Moderately critical - Access bypass - SA-CONTRIB-2025-097Drupal Layout Builder Advanced Permissions
CVE-2025-8995Authenticator Login - Highly critical - Access bypass - SA-CONTRIB-2025-096Drupal Authenticator Login
CVE-2025-8675AI SEO Link Advisor - Less critical - Server-side Request Forgery - SA-CONTRIB-2025-095Drupal AI SEO Link Advisor
CVE-2025-8362GoogleTag Manager - Moderately critical - Cross-site scripting - SA-CONTRIB-2025-094Drupal GoogleTag Manager
CVE-2025-8361Config Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-093Drupal Config Pages
CVE-2025-8093Authenticator Login - Moderately critical - Access bypass - SA-CONTRIB-2025-098Drupal Authenticator Login
CVE-2025-8092COOKiES Consent Management - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-092Drupal COOKiES Consent Management
CVE-2025-7717File Download - Moderately critical - Access bypass - SA-CONTRIB-2025-089Drupal File Download
CVE-2025-7716Real-time SEO for Drupal - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-091Drupal
CVE-2025-7715Block Attributes - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-090Drupal Block Attributes
CVE-2025-7393Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088Drupal Mail Login
CVE-2025-7392Cookies Addons - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-087Drupal Cookies Addons
CVE-2025-7031Config Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086Drupal Config Pages Viewer
CVE-2025-7030Two-factor Authentication (TFA) - Less critical - Access bypass - SA-CONTRIB-2025-085Drupal Two-factor Authentication (TFA)
CVE-2025-6677Paragraphs table - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-084Drupal Paragraphs table
CVE-2025-6676Simple XML sitemap - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-083Drupal Simple XML sitemap
CVE-2025-6675Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-082Drupal
CVE-2025-6674CKEditor5 Youtube - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-081Drupal CKEditor5 Youtube
CVE-2025-5682Klaro Cookie & Consent Management - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-080Drupal Klaro Cookie & Consent Management
CVE-2025-48923Toc.js - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-077Drupal Toc.js
CVE-2025-48922GLightbox - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-078Drupal GLightbox
CVE-2025-48921Open Social - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-079Drupal Open Social
CVE-2025-48920etracker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-074Drupal etracker
CVE-2025-48919Simple Klaro - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-073Drupal Simple Klaro
CVE-2025-48918Simple Klaro - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-071Drupal Simple Klaro
CVE-2025-48917EU Cookie Compliance (GDPR Compliance) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-072Drupal EU Cookie Compliance (GDPR Compliance)
CVE-2025-48916Bookable Calendar - Less critical - Access bypass - SA-CONTRIB-2025-070Drupal Bookable Calendar
CVE-2025-48915COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-076Drupal COOKiES Consent Management
CVE-2025-48914COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-075Drupal COOKiES Consent Management
CVE-2025-48448Admin Audit Trail - Less critical - Denial of Service - SA-CONTRIB-2025-068Drupal Admin Audit Trail
CVE-2025-48447Lightgallery - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-069Drupal Lightgallery
CVE-2025-48446Commerce Alphabank Redirect - Moderately critical - Access bypass - SA-CONTRIB-2025-067Drupal Commerce Alphabank Redirect
CVE-2025-48445Commerce Eurobank (Redirect) - Moderately critical - Access bypass - SA-CONTRIB-2025-066Drupal Commerce Eurobank (Redirect)
CVE-2025-48444Quick Node Block - Moderately critical - Access bypass - SA-CONTRIB-2025-064Drupal Quick Node Block
CVE-2025-48013Quick Node Block - Moderately critical - Access bypass - SA-CONTRIB-2025-065Drupal Quick Node Block
CVE-2025-48012One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-063Drupal One Time Password
CVE-2025-48011One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-062Drupal One Time Password
CVE-2025-48010One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-061Drupal One Time Password
CVE-2025-48009Single Content Sync - Moderately critical - Access bypass - SA-CONTRIB-2025-060Drupal Single Content Sync
CVE-2025-47710Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-056Drupal
CVE-2025-47709Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-055Drupal
CVE-2025-47708Enterprise MFA - TFA for Drupal - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-054Drupal
CVE-2025-47707Enterprise MFA - TFA for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2025-053Drupal
CVE-2025-47706Enterprise MFA - TFA for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2025-052Drupal
CVE-2025-47705IFrame Remove Filter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-051Drupal IFrame Remove Filter
CVE-2025-47704Klaro Cookie & Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-050Drupal Klaro Cookie & Consent Management
CVE-2025-47703COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-049Drupal COOKiES Consent Management
CVE-2025-47702oEmbed Providers - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-048Drupal oEmbed Providers
CVE-2025-47701Restrict route by IP - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-047Drupal Restrict route by IP
CVE-2025-4416Events Log Track - Moderately critical - Denial of Service - SA-CONTRIB-2025-059Drupal Events Log Track
CVE-2025-4415Piwik PRO - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-058Drupal Piwik PRO
CVE-2025-3907Search API Solr - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-046Drupal Search API Solr
CVE-2025-3904Sportsleague - Critical - Unsupported - SA-CONTRIB-2025-045Drupal Sportsleague
CVE-2025-3903UEditor - 百度编辑器 - Critical - Unsupported - SA-CONTRIB-2025-044Drupal UEditor - 百度编辑器
CVE-2025-3902Block Class - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-043Drupal Block Class
CVE-2025-3901Bootstrap Site Alert - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-042Drupal Bootstrap Site Alert

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.