3.5
CVE-2024-13261 - Acquia DAM - Moderately critical - Cross Site Request Forgery, Denial of Service - SA-CONTRIB-2024-โฆ
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.
8.8
CVE-2024-13260 - Migrate queue importer - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-024
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.
7.5
CVE-2024-13259 - Image Sizes - Moderately critical - Access bypass - SA-CONTRIB-2024-023
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.
9.8
CVE-2024-13258 - Drupal REST & JSON API Authentication - Moderately critical - Access bypass - SA-CONTRIB-2024-022
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.
5.3
CVE-2024-13257 - Commerce View Receipt - Moderately critical - Access bypass - SA-CONTRIB-2024-021
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.
7.5
CVE-2024-13256 - Email Contact - Moderately critical - Access bypass - SA-CONTRIB-2024-020
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.
7.5
CVE-2024-13255 - RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.
7.5
CVE-2024-13254 - REST Views - Moderately critical - Information Disclosure - SA-CONTRIB-2024-018
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.
9.1
CVE-2024-13253 - Advanced PWA - Critical - Access bypass - SA-CONTRIB-2024-017
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.
5.4
CVE-2024-13252 - TacJS - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-016
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allows Cross-Site Scripting (XSS).This issue affects TacJS: from 0.0.0 before 6.5.0.