CVE-2026-15916
- EPSS 0.12%
- Veröffentlicht 25.08.2026 22:22:27
- Zuletzt bearbeitet 28.08.2026 15:29:44
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 ...
CVE-2026-15917
- EPSS 0.13%
- Veröffentlicht 25.08.2026 22:22:23
- Zuletzt bearbeitet 28.08.2026 15:29:44
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0...
CVE-2026-55805
- EPSS 0.13%
- Veröffentlicht 25.08.2026 22:22:20
- Zuletzt bearbeitet 28.08.2026 15:29:44
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4,...
CVE-2026-55808
- EPSS 0.16%
- Veröffentlicht 10.07.2026 21:46:43
- Zuletzt bearbeitet 16.07.2026 15:02:57
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 1...
CVE-2026-55807
- EPSS 0.14%
- Veröffentlicht 10.07.2026 21:46:40
- Zuletzt bearbeitet 16.07.2026 14:58:17
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0....
CVE-2026-55804
- EPSS 0.22%
- Veröffentlicht 10.07.2026 21:46:39
- Zuletzt bearbeitet 16.07.2026 15:11:21
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14...
CVE-2026-55806
- EPSS 0.21%
- Veröffentlicht 10.07.2026 21:46:39
- Zuletzt bearbeitet 16.07.2026 15:26:23
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, f...
CVE-2026-55803
- EPSS 0.22%
- Veröffentlicht 10.07.2026 21:46:38
- Zuletzt bearbeitet 16.07.2026 15:09:30
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14...
CVE-2026-9082
- EPSS 88.32%
- Veröffentlicht 20.05.2026 18:20:52
- Zuletzt bearbeitet 07.10.2026 19:17:45
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before ...
CVE-2026-6367
- EPSS 0.2%
- Veröffentlicht 19.05.2026 22:28:07
- Zuletzt bearbeitet 24.07.2026 08:10:00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.