Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities BSI Germany

[NEU] [hoch] Drupal Extensions: Mehrere Schwachstellen

Multiple critical vulnerabilities across numerous Drupal extensions allow attackers to bypass security measures, disclose sensitive information, manipulate data, and conduct cross-site scripting attacks via remote exploitation. The CVSS Base Score for this collection of vulnerabilities is 9.4 (Critical). The advisory lists specific affected versions for over a dozen extensions, such as Drupal Address Suggestion before 1.0.25 and Drupal Blazy before 3.0.18. Mitigation is available, though the specific fixed versions or patch details are not provided in the summary.
Read Full Article →

[WID-SEC-2026-3041] Drupal Extensions: Mehrere Schwachstellen CVSS Base Score 9.4 (kritisch) CVSS Temporal Score 8.2 (hoch) Remoteangriff ja Datum 26.08.2026 Stand 27.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 26.08.2026 Open Source Drupal Address Suggestion <1.0.25 Open Source Drupal Blazy <3.0.18 Open Source Drupal CAPTCHA Protected Page <1.0.2 Open Source Drupal Commerce CyberSource <1.10.0 Open Source Drupal Content Moderation Notifications <3.9.0 Open Source Drupal Data field <2.0.13 Open Source Drupal Digital Signage Framework <2.6.1 Open Source Drupal Disable Login Page <1.1.4 Open Source Drupal DXPR Builder <2.8.1 Open Source Drupal Entity API <1.8.0 Open Source Drupal Entity PDF <2.1.5 Open Source Drupal LDAP / Active Directory Integration <2.2.1 Open Source Drupal Monster Menus <9.5.3 Open Source Drupal Slick Carousel <2.1.0 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um Sicherheitsmaßnahmen zu umgehen, sensible Informationen offenzulegen, Daten zu manipulieren und Cross-Site-Scripting-Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article