Showing 2 vulnerabilities on this page for ECA: Event - Condition - Action

Signals CISA KEV Ransomware Nuclei
Drupal vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.

CWE-915Jul 10, 2026
CVSS4.2v3.1EPSS0.179%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ECA: Event - Condition - Action - Critical - Cross site request forgery - SA-CONTRIB-2025-031

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.

CWE-352Apr 9, 2025
CVSS5.4v3.1EPSS0.168%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX