Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities BSI Germany

[NEU] [hoch] Drupal Erweiterungen: Mehrere Schwachstellen

Multiple critical vulnerabilities in specific Drupal extensions allow remote, anonymous attackers to bypass access controls, expose sensitive data, take over accounts, perform unauthorized modifications, and execute cross-site scripting attacks. The advisory notes a CVSS Base Score of 9.1 (Critical) and a Temporal Score of 7.9 (High). Affected extensions include Drupal AI before version 1.4.8, Drupal Advanced Search before 2.4.5, Drupal AI Translate before 1.4.1, and numerous others listed with their specific vulnerable version ranges.
Read Full Article →

[WID-SEC-2026-3168] Drupal Erweiterungen: Mehrere Schwachstellen CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 7.9 (hoch) Remoteangriff ja Datum 02.09.2026 Stand 03.09.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 02.09.2026 Open Source Drupal AI <1.4.8 Open Source Drupal Advanced Search <2.4.5 Open Source Drupal AI Translate <1.4.1 Open Source Drupal Calculate Working Days <2.0.3 Open Source Drupal Component Blocks <1.2.7 Open Source Drupal Email Verification / SMS Verification / OTP Verification <2.4.0 Open Source Drupal Islandora <2.19.0 Open Source Drupal Jsonapi Role Access <2.0.2 Open Source Drupal Mailer Plus Log <1.2.7 Open Source Drupal Media Library Importer <2.1.6 Open Source Drupal Monobank Payment API <1.0.3 Open Source Drupal PhotoSwipe <5.0.9 Open Source Drupal Unpublished Node Permissions <1.8.0 Open Source Drupal Webform Submissions Delete <1.2.0 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um Zugriffsbeschränkungen zu umgehen, geschützte oder sensible Inhalte offenzulegen, Benutzerkonten zu übernehmen, unberechtigte Änderungen oder Löschungen vorzunehmen, Zahlungsstatus zu manipulieren sowie Cross-Site-Scripting-Angriffe auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article