drupal

509 tracked vulnerabilities.

CVE-2025-10930 MEDIUM
Drupal Currency < 3.5.0 - Cross-Site Request Forgery
Oct 30, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-10929 MEDIUM
Drupal Reverse Proxy Header <1.1.2 - Info Disclosure
Oct 30, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-10928 MEDIUM
Drupal Access code < 2.0.5 - Brute Force via Excessive Authentication Attempts
Oct 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-10927 MEDIUM
Plausible tracking < 1.0.2 - Cross-Site Scripting
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-10926 MEDIUM
Drupal JSON Field < 1.5 - Cross-Site Scripting
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-9551 MEDIUM
Drupal Protected Pages <1.8.0 - Auth Bypass
Oct 10, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-48915 HIGH
Drupal COOKiES Consent Mgmt <1.2.15 - XSS
Jun 13, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-48914 HIGH
Drupal COOKiES Consent Mgmt <1.2.15 - XSS
Jun 13, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-48448 MEDIUM
Drupal Admin Audit Trail <1.0.5 - Info Disclosure
Jun 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-48447 HIGH
Drupal Lightgallery < 1.6.0 - Cross-Site Scripting
Jun 11, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-48446 HIGH
Drupal Commerce Alphabank Redirect <1.0.3 - Auth Bypass
Jun 11, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-48445 HIGH
Drupal Commerce Eurobank (Redirect) <2.1.1 - Functionality Misuse
Jun 11, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-48444 MEDIUM
Drupal Quick Node Block <2.0.0 - Info Disclosure
Jun 11, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-48013 MEDIUM
Drupal Quick Node Block < 2.0.0 - Missing Authorization
Jun 11, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3474 MEDIUM
Drupal Panels < 4.9 - Unauthenticated Access Control Bypass via Incorrectly Configured Security Levels
Apr 09, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-3131 MEDIUM
Drupal ECA < 1.1.12, 2.0.0-2.0.15, 2.1.0-2.1.6 - Cross-Site Request Forgery
Apr 09, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-3130 MEDIUM
Drupal Obfuscate < 2.0.1 - Stored Cross-Site Scripting
Apr 02, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-3057 MEDIUM
Drupal 8.0.0-10.3.12, 10.4.0-10.4.2, 11.0.0-11.0.11, 11.1.0-11.1.2 - Cross-Site Scripting
Mar 31, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-31697 MEDIUM
Drupal Formatter Suite <2.1.0 - XSS
Mar 31, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-31696 MEDIUM
Drupal RapiDoc OAS Field Formatter <1.0.1 - XSS
Mar 31, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-31695 MEDIUM
Drupal Link field display mode formatter < 1.6.0 - Cross-Site Scripting
Mar 31, 2025
CVSS 6.1
EPSS 0.01
CVE-2025-31694 HIGH
Drupal Two-factor Authentication < 1.10.0 - Authentication Bypass via Forceful Browsing
Mar 31, 2025
CVSS 8.1
EPSS 0.01
CVE-2025-31693 MEDIUM
Drupal AI <1.0.5 - Command Injection
Mar 31, 2025
CVSS 6.6
EPSS 0.00
CVE-2025-31692 HIGH
Drupal AI <1.0.5 - Command Injection
Mar 31, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-31691 CRITICAL
Drupal OAuth2 Server <2.1.0 - Info Disclosure
Mar 31, 2025
CVSS 9.8
EPSS 0.00