8.8
CVE-2025-31690 - Cache Utility - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-019
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.
8.1
CVE-2025-31689 - General Data Protection Regulation - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-โฆ
Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.
6.8
CVE-2025-31688 - Configuration Split - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-017
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This issue affects Configuration Split: from 0.0.0 before 1.10.0, from 2.0.0 before 2.0.2.
6.1
CVE-2025-31687 - SpamSpan filter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-016
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SpamSpan filter allows Cross-Site Scripting (XSS).This issue affects SpamSpan filter: from 0.0.0 before 3.2.1.
8.1
CVE-2025-31686 - Open Social - Less critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-015
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.
9.1
CVE-2025-31685 - Open Social - Moderately critical - Access bypass - SA-CONTRIB-2025-014
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.
6.8
CVE-2025-31684 - OAuth2 Client - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-013
Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3.
6.8
CVE-2025-31683 - Google Tag - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-012
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
4.8
CVE-2025-31682 - Google Tag - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-011
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
9.8
CVE-2025-31681 - Authenticator Login - Critical - Access bypass - SA-CONTRIB-2025-009
Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.