6.8
CVE-2025-31684 - OAuth2 Client - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-013
Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3.
6.8
CVE-2025-31683 - Google Tag - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-012
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
4.8
CVE-2025-31682 - Google Tag - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-011
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
9.8
CVE-2025-31681 - Authenticator Login - Critical - Access bypass - SA-CONTRIB-2025-009
Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.
6.8
CVE-2025-31680 - Matomo Analytics - Moderately critical - Cross site request forgery - SA-CONTRIB-2025-008
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.
6.1
CVE-2025-31679 - Ignition Error Pages - Critical - Cross Site Scripting - SA-CONTRIB-2025-007
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Error Pages allows Cross-Site Scripting (XSS).This issue affects Ignition Error Pages: from 0.0.0 before 1.0.4.
8.2
CVE-2025-31678 - AI (Artificial Intelligence) - Moderately critical - Access bypass, Information Disclosure - SA-CONβ¦
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.
8.8
CVE-2025-31677 - AI (Artificial Intelligence) - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-003
Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Intelligence): from 1.0.0 before 1.0.2.
8.8
CVE-2025-31676 - Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
5.4
CVE-2025-31675 - Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.Β It β¦