PatchSiren

Drupal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-81205

CVE-2026-81205 is a MEDIUM-severity LDAP Injection vulnerability in the Drupal LDAP / Active Directory Integration module, affecting versions from 0.0.0 to 2.2.1. Defenders should prioritize verifying and applying patches, assessing exposure, and updating inventory of affected systems. The CVE record was published on 2026-09-02T13:18:12.803Z and has not been modified since then. The NVD entry is currently [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-81166

A Missing Authorization vulnerability in the Drupal Digital Signage Framework allows for Forceful Browsing. This issue affects Digital Signage Framework versions from 0.0.0 to 2.6.1. The vulnerability could allow attackers to access sensitive information or perform unauthorized actions. Defenders should assess exposure and prioritize remediation based on the potential impact on Digital Signage Framework d [truncated]

LOW Drupal CVE published 2026-09-02

CVE-2026-81159

A CVE record for an Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource was published on 2026-09-02. The vulnerability allows for Brute Force attacks and affects Commerce CyberSource versions from 0.0.0 to 1.10.0. This issue has a CVSS score of 3.7 and is considered LOW severity. Defenders and administrators using Commerce CyberSource, especially those with versions prior to 1.10.0, [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-76757

A vulnerability in the Drupal Gammu SMS Daemon affects versions *.*. The issue has a CVSS score of 5.9 and is classified as MEDIUM severity. The CVE record was published on 2026-09-02T13:18:10.977Z and was last modified on 2026-09-19T16:16:31.030Z. This vulnerability requires verification of affected versions and monitoring for potential exploitation attempts. Defenders should assess exposure and prioriti [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-76756

A vulnerability in the Drupal Gammu SMS Daemon affects versions *.*. The issue has a CVSS score of 5.9 and is classified as MEDIUM severity. The CVE record was published on 2026-09-02T13:18:10.883Z and was last modified on 2026-09-19T15:17:01.910Z. Defenders responsible for maintaining and securing systems that use the Gammu SMS Daemon should assess exposure to this vulnerability and prioritize verificati [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-76755

A vulnerability exists in the Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. The CVSS score is 5.9, and the severity is MEDIUM. The vulnerability is classified as a result of insufficient validation of user input. Defenders responsible for Drupal Gammu SMS Daemon installations should assess exposure and prioritize verification of affected versions and potential impact. The CVE [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-73477

The CVE-2026-73477 vulnerability in the Drupal Quick Tabs module allows for forceful browsing due to incorrect authorization. This issue affects Quick Tabs versions from 0.0.0 to 4.3.1. The CVSS score is 5.3, indicating a medium severity. The CVE was published on 2026-09-02 and last modified on 2026-09-16. Defenders should verify the versions of Quick Tabs in use and assess exposure, especially in environ [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-73476

A CVE record for Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation was published on 2026-09-02T13:18:08.413Z and last modified on 2026-09-15T12:28:25.280Z. The NVD entry is currently Analyzed. Defenders should prioritize verifying exposure in their Drupal External Authentication deployments, especially those using versions up to 2.0.13, and a [truncated]

CRITICAL Drupal CVE published 2026-09-02

CVE-2026-73475

CVE-2026-73475 is an Incorrect Authorization vulnerability in Drupal Commerce PayPal, allowing for Forceful Browsing. The issue affects Commerce PayPal versions from 0.0.0 to 1.12.0 and from 2.0.0 to 2.1.3. This vulnerability has a CVSS score of 9.1, indicating a Critical severity. Defenders and administrators using Drupal Commerce PayPal, especially those with versions within the affected ranges, should [truncated]

MEDIUM Drupal CVE published 2026-09-02

CVE-2026-16647

CVE-2026-16647 is an Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page. The issue affects Disable Login Page versions from 0.0.0 to 1.1.4. According to the CVE Program and NVD, the vulnerability has a CVSS score of 4.1 and is classified as MEDIUM severity. This vulnerability allows for authentication bypass using an alternate path or channel, potentially l [truncated]

MEDIUM Drupal CVE published 2026-08-25

CVE-2026-18260

The CVE-2026-18260 vulnerability is an Improper Restriction of Excessive Authentication Attempts issue in the Drupal Disable Login Page module. This vulnerability allows for brute-force attacks and affects versions from 0.0.0 to 1.1.4. The CVSS score is 5.7, indicating a MEDIUM severity. Affected Drupal users should review their installations and apply patches or mitigations as necessary. The Disable Logi [truncated]

MEDIUM Drupal CVE published 2026-08-25

CVE-2026-16646

A CVE record for a vulnerability in Drupal PanKM was published on 2026-08-25T23:16:57.423Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects Drupal PanKM versions *.*. The CVSS score is 5.7 with MEDIUM severity. Limited information is available; further details are needed for comprehensive assessment. Users should verify affected versions and monitor for [truncated]

MEDIUM Drupal CVE published 2026-08-25

CVE-2026-16640

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T23:16:56.787Z and has not been modified since then. The CVE-2026-16640 vulnerability is an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) issue in Drupal Search API Autocomplete. This issue allows for reflected XSS and affects versions from 0.0.0 to 1.12.0, wit [truncated]

MEDIUM Drupal CVE published 2026-08-25

CVE-2026-16638

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T23:16:56.560Z and has not been modified since then. CVE-2026-16638 indicates a Stored XSS vulnerability in Drupal Media Folders versions from 0.0.0 to 1.0.8 due to improper neutralization of input during web page generation. This vulnerability allows attackers to inject malicious scripts, potenti [truncated]

MEDIUM Drupal CVE published 2026-08-25

CVE-2026-15917

CVE-2026-15917 is an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in Drupal core. The vulnerability affects Drupal core versions from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, and all versions prior to 11.2.*. This issue allows attackers to inject malicious scripts into web pages viewed by users of affected Drupal installations. Drupal users and administ [truncated]

MEDIUM Drupal CVE published 2026-08-25

CVE-2026-15916

CVE-2026-15916 is a Missing Authorization vulnerability in Drupal core that allows for Forceful Browsing. The vulnerability affects multiple versions of Drupal core, including 0.0.0 to 10.6.13, 11.3.0 to 11.3.14, and 11.4.0 to 11.4.4. The CVSS score for this vulnerability is 4.2, indicating a medium severity level. This issue was published on 2026-08-25T23:16:56.320Z and has not been modified since then. [truncated]

CRITICAL Drupal CVE published 2026-07-10

CVE-2026-15089

A vulnerability exists in Drupal Commerce guest registration, allowing potential security issues with guest registration. The CVE record was published on 2026-07-10T23:16:47.533Z and has not been modified since then. This issue affects Commerce guest registration versions: *.*. Users should review their installations for potential vulnerabilities and apply vendor patches or updates.

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-15087

The Clean RESTful module for Drupal has a vulnerability. This issue affects Clean RESTful versions: *.*. The CVE record was published on 2026-07-10T23:16:47.430Z and has not been modified since then. Drupal users and administrators should review and apply patches for Clean RESTful. The vulnerability's operational impact and source-confidence limits should be considered.

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-15086

The CVE record for CVE-2026-15086 was published on 2026-07-10T23:16:47.330Z and has not been modified since then. This vulnerability affects Drupal Raw Formatter [Meta Tag Formatter] versions: *.*. Users should review the vulnerability details and apply patches or mitigations as recommended by the vendor. The debrief provides an executive overview of the vulnerability, its likely operational impact, and r [truncated]

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-11915

A vulnerability in Drupal Brute force attack protection allows an attacker to perform a brute force attack. This issue affects Brute force attack protection versions: *.*. The vulnerability has been publicly disclosed and users of Drupal Brute force attack protection should review and apply the necessary updates. However, detailed technical information is limited, and additional review is required to unde [truncated]

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-11914

A vulnerability in Drupal Composer has been reported, potentially affecting various Composer versions. The issue's nature and impact are not fully understood due to limited available information. Users of Drupal Composer should review the official CVE record and assess the vulnerability's impact on their systems. The CVE record was published on 2026-07-10T23:16:46.843Z and has not been modified since then.

CRITICAL Drupal CVE published 2026-07-10

CVE-2026-11913

A PatchSiren debrief for CVE-2026-11913, a vulnerability in Drupal Mother May I, was generated based on the supplied source corpus. This vulnerability has been identified in Drupal Mother May I versions *.*, and users of these versions should review the vulnerability details and assess their exposure. The CVE record was published on 2026-07-10T23:16:46.490Z and has not been modified since then. Limited in [truncated]

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-58591

The CVE-2026-58591 vulnerability is a Cross-Site Scripting (XSS) issue in Drupal Colorbox, affecting versions from 0.0.0 to 2.1.5 and from 0.0.0 to 2.2.0. This Improper Neutralization of Input During Web Page Generation vulnerability allows attackers to inject malicious scripts into web pages viewed by users of the affected Colorbox versions. Users should review their deployments and apply necessary patch [truncated]

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-58590

A Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions from 0.0.0 to 1.6.0. The vulnerability could allow attackers to perform unauthorized actions, potentially leading to Forceful Browsing attacks. Users of affected versions should review and apply necessary patches to prevent potential attacks.

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-58589

A Missing Authorization vulnerability was reported in Drupal FlowDrop, which could allow Forceful Browsing. This issue affects FlowDrop versions from 0.0.0 to 1.6.0. The vulnerability has a medium priority due to potential for unauthorized access. Users of Drupal FlowDrop versions from 0.0.0 to 1.6.0 should assess the vulnerability and apply patches or mitigations as necessary. Evidence is limited; primar [truncated]

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-58588

The CVE record for CVE-2026-58588 was published on 2026-07-10T22:16:45.070Z and has not been modified since then. This Cross-Site Scripting (XSS) vulnerability affects Drupal Canvas versions from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, and from 1.7.0 to 1.7.1. Users of affected versions should be aware of this vulnerability and take necessary precautions.

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-58587

The CVE-2026-58587 vulnerability is a Cross-site Scripting (XSS) issue affecting Drupal Canvas. It impacts versions from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, and from 1.7.0 to 1.7.1. Users of affected versions should apply vendor remediation. The vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Sec [truncated]

HIGH Drupal CVE published 2026-07-10

CVE-2026-55810

CVE-2026-55810 is an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing, which allows Object Injection. The issue affects Plotly.js Graphing versions from 0.0.0 to 3.0.2. Limited evidence is available for this CVE. To verify affected systems, check for Plotly.js Graphing versions within the vulnerable range and review Drupal's security [truncated]

HIGH Drupal CVE published 2026-07-10

CVE-2026-55809

The CVE-2026-55809 vulnerability is an Improperly Controlled Modification of Dynamically-Determined Object Attributes issue in the Drupal Flag attendance field module, allowing for Object Injection. This affects versions from 0.0.0 to 1.2 of the module. Users should review the official CVE record and apply patches or mitigations as available. The vulnerability has a medium priority for users of affected D [truncated]

MEDIUM Drupal CVE published 2026-07-10

CVE-2026-55808

The CVE-2026-55808 vulnerability is a Cross-Site Scripting (XSS) issue in Drupal core, allowing for XSS attacks. Affected versions include from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, and from 0.0.0 to 11.1.*. The CVE record was published on 2026-07-10T22:16:43.667Z and has not been modified since then. This issue has a high impact on [truncated]