[WID-SEC-2026-2474] Drupal Module: Mehrere Schwachstellen CVSS Base Score 7.4 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff ja Datum 22.07.2026 Stand 23.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 22.07.2026 Open Source Drupal Media Folders <1.0.8 Open Source Drupal Search API Autocomplete <1.12.0 Open Source Drupal Internationalization Single Sign-On <1.8.0 Open Source Drupal Webform REST <4.1.0 Open Source Drupal PanKM Open Source Drupal Commerce Elavon Open Source Drupal Email Login OTP Open Source Drupal Lunr exposed filters Open Source Drupal Development Environment Open Source Drupal PhotoSwipe <3.2.0 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und weitere, nicht näher spezifizierte Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in several Drupal modules, including Media Folders (<1.0.8) and Search API Autocomplete (<1.12.0), can be exploited remotely to conduct cross-site scripting attacks, bypass security measures, and disclose sensitive information. The CVSS Base Score for these issues is 7.4 (High). A mitigation is available, and administrators should apply updates to the patched versions specified in the advisory for each affected module.