9.8

CVSS3.1

CVE-2024-13280 - Persistent Login - Moderately critical - Access bypass - SA-CONTRIB-2024-044

Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.

πŸ“… Published: Jan. 9, 2025, 7:34 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:28 p.m.

9.8

CVSS3.1

CVE-2024-13279 - Two-factor Authentication (TFA) - Critical - Access bypass - SA-CONTRIB-2024-043

Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.

πŸ“… Published: Jan. 9, 2025, 7:31 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:28 p.m.

9.1

CVSS3.1

CVE-2024-13278 - Diff - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-042

Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

πŸ“… Published: Jan. 9, 2025, 7:31 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:28 p.m.

9.1

CVSS3.1

CVE-2024-13277 - Smart IP Ban - Critical - Access bypass - SA-CONTRIB-2024-041

Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.

πŸ“… Published: Jan. 9, 2025, 7:29 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.

7.5

CVSS3.1

CVE-2024-13276 - File Entity (fieldable files) - Moderately critical - Information Disclosure - SA-CONTRIB-2024-040

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.

πŸ“… Published: Jan. 9, 2025, 7:28 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.

5.3

CVSS3.1

CVE-2024-13275 - Security Kit - Less critical - Denial of Service - SA-CONTRIB-2024-039

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.

πŸ“… Published: Jan. 9, 2025, 7:27 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 6:29 p.m.

5.3

CVSS3.1

CVE-2024-13274 - Open Social - Moderately critical - Denial of Service - SA-CONTRIB-2024-038

Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.

πŸ“… Published: Jan. 9, 2025, 7:27 p.m. πŸ”„ Last Modified: Jan. 14, 2025, 5:15 p.m.

5.4

CVSS3.1

CVE-2024-13273 - Open Social - Moderately critical - Cross Site Scripting, Denial of Service - SA-CONTRIB-2024-037

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.

πŸ“… Published: Jan. 9, 2025, 7:26 p.m. πŸ”„ Last Modified: Aug. 28, 2025, 1:03 p.m.

9.8

CVSS3.1

CVE-2024-10215 - WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticat…

πŸ“… Published: Jan. 9, 2025, 7:21 p.m. πŸ”„ Last Modified: April 8, 2026, 4:44 p.m.

6.3

CVSS3.1

CVE-2024-13272 - Paragraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-036

Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.

πŸ“… Published: Jan. 9, 2025, 7:20 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 7:23 p.m.
Total resulsts: 345149
Page 6795 of 34,515
Β« previous page Β» next page
Filters