5.3
CVE-2024-13290 - OhDear Integration - Moderately critical - Access bypass - SA-CONTRIB-2024-056
Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.
5.4
CVE-2024-13289 - Cookiebot + GTM - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-055
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.
4.3
CVE-2024-13288 - Monster Menus - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-052
Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.
5.4
CVE-2024-13287 - Views SVG Animation - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-051
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG Animation allows Cross-Site Scripting (XSS).This issue affects Views SVG Animation: from 0.0.0 before 1.0.1.
5.4
CVE-2024-13286 - SVG Embed - Moderately critical - Cross site scripting - SA-CONTRIB-2024-050
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed allows Cross-Site Scripting (XSS).This issue affects SVG Embed: from 0.0.0 before 2.1.2.
9.8
CVE-2024-13285 - wkhtmltopdf - Highly critical - Unsupported - SA-CONTRIB-2024-049
Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.
8.8
CVE-2024-13284 - Gutenberg - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-048
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.
6.1
CVE-2024-13283 - Facets - Critical - Cross Site Scripting - SA-CONTRIB-2024-047
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.9.
8.8
CVE-2024-13282 - Block permissions - Moderately critical - Access bypass - SA-CONTRIB-2024-046
Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.
9.1
CVE-2024-13281 - Monster Menus - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-045
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.