These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability exists in Drupal Commerce guest registration, allowing potential security issues with guest registration. The CVE record was published on 2026-07-10T23:16:47.533Z and has not been modified since then. This issue affects Commerce guest registration versions: *.*. Users should review their installations for potential vulnerabilities and apply vendor patches or updates.
The Clean RESTful module for Drupal has a vulnerability. This issue affects Clean RESTful versions: *.*. The CVE record was published on 2026-07-10T23:16:47.430Z and has not been modified since then. Drupal users and administrators should review and apply patches for Clean RESTful. The vulnerability's operational impact and source-confidence limits should be considered.
The CVE record for CVE-2026-15086 was published on 2026-07-10T23:16:47.330Z and has not been modified since then. This vulnerability affects Drupal Raw Formatter [Meta Tag Formatter] versions: *.*. Users should review the vulnerability details and apply patches or mitigations as recommended by the vendor. The debrief provides an executive overview of the vulnerability, its likely operational impact, and r [truncated]
A vulnerability in Drupal Brute force attack protection allows an attacker to perform a brute force attack. This issue affects Brute force attack protection versions: *.*. The vulnerability has been publicly disclosed and users of Drupal Brute force attack protection should review and apply the necessary updates. However, detailed technical information is limited, and additional review is required to unde [truncated]
A vulnerability in Drupal Composer has been reported, potentially affecting various Composer versions. The issue's nature and impact are not fully understood due to limited available information. Users of Drupal Composer should review the official CVE record and assess the vulnerability's impact on their systems. The CVE record was published on 2026-07-10T23:16:46.843Z and has not been modified since then.
A PatchSiren debrief for CVE-2026-11913, a vulnerability in Drupal Mother May I, was generated based on the supplied source corpus. This vulnerability has been identified in Drupal Mother May I versions *.*, and users of these versions should review the vulnerability details and assess their exposure. The CVE record was published on 2026-07-10T23:16:46.490Z and has not been modified since then. Limited in [truncated]
The CVE-2026-58591 vulnerability is a Cross-Site Scripting (XSS) issue in Drupal Colorbox, affecting versions from 0.0.0 to 2.1.5 and from 0.0.0 to 2.2.0. This Improper Neutralization of Input During Web Page Generation vulnerability allows attackers to inject malicious scripts into web pages viewed by users of the affected Colorbox versions. Users should review their deployments and apply necessary patch [truncated]
A Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions from 0.0.0 to 1.6.0. The vulnerability could allow attackers to perform unauthorized actions, potentially leading to Forceful Browsing attacks. Users of affected versions should review and apply necessary patches to prevent potential attacks.
A Missing Authorization vulnerability was reported in Drupal FlowDrop, which could allow Forceful Browsing. This issue affects FlowDrop versions from 0.0.0 to 1.6.0. The vulnerability has a medium priority due to potential for unauthorized access. Users of Drupal FlowDrop versions from 0.0.0 to 1.6.0 should assess the vulnerability and apply patches or mitigations as necessary. Evidence is limited; primar [truncated]
The CVE record for CVE-2026-58588 was published on 2026-07-10T22:16:45.070Z and has not been modified since then. This Cross-Site Scripting (XSS) vulnerability affects Drupal Canvas versions from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, and from 1.7.0 to 1.7.1. Users of affected versions should be aware of this vulnerability and take necessary precautions.
The CVE-2026-58587 vulnerability is a Cross-site Scripting (XSS) issue affecting Drupal Canvas. It impacts versions from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, and from 1.7.0 to 1.7.1. Users of affected versions should apply vendor remediation. The vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Sec [truncated]
CVE-2026-55810 is an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing, which allows Object Injection. The issue affects Plotly.js Graphing versions from 0.0.0 to 3.0.2. Limited evidence is available for this CVE. To verify affected systems, check for Plotly.js Graphing versions within the vulnerable range and review Drupal's security [truncated]
The CVE-2026-55809 vulnerability is an Improperly Controlled Modification of Dynamically-Determined Object Attributes issue in the Drupal Flag attendance field module, allowing for Object Injection. This affects versions from 0.0.0 to 1.2 of the module. Users should review the official CVE record and apply patches or mitigations as available. The vulnerability has a medium priority for users of affected D [truncated]
The CVE-2026-55808 vulnerability is a Cross-Site Scripting (XSS) issue in Drupal core, allowing for XSS attacks. Affected versions include from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, and from 0.0.0 to 11.1.*. The CVE record was published on 2026-07-10T22:16:43.667Z and has not been modified since then. This issue has a high impact on [truncated]
A Server-Side Request Forgery (SSRF) vulnerability exists in Drupal core. The issue affects multiple Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, and from 0.0.0 to 11.1.*. Evidence is limited; further verification is required to confirm affected scope and vendor remediation. This vulnerability is classified under CWE-918.
CVE-2026-55806 is a URL Redirection to Untrusted Site vulnerability in Drupal Core. This issue allows Content Spoofing and affects multiple Drupal core versions. The vulnerability could potentially allow attackers to redirect users to untrusted sites, leading to phishing attacks or other malicious activities. Users of affected versions should prioritize updating to the latest version of Drupal core to mit [truncated]
CVE-2026-55804 is an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal core, potentially allowing Object Injection. Affected versions include Drupal core from 0.0.0 to 10.5.12, 10.6.0 to 10.6.11, 11.2.0 to 11.2.14, and 11.3.0 to 11.3.12. For more information, refer to the official CVE record and NVD detail. Users of Drupal core within these versions sho [truncated]
The CVE-2026-55803 vulnerability is classified as an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal core, which allows Object Injection. This issue affects Drupal core versions from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, and from 0.0.0 to 11.1.*. The vulnerability has a high imp [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:41.230Z and has not been modified since then. This Stored XSS vulnerability in Drupal AI SEO/GEO Analyzer allows attackers to inject malicious scripts. Users of affected versions from 0.0.0 to 1.1.3 should assess and apply patches. The vulnerability has a medium priority for users of affect [truncated]
The CVE-2026-15084 vulnerability is a Stored Cross-site Scripting (XSS) issue in Drupal UI Patterns (SDC in Drupal UI) versions from 2.0.0 to 2.0.17. This Improper Neutralization of Input During Web Page Generation vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Users of affected versions should review and apply patch [truncated]
The CVE-2026-15083 vulnerability is an Improperly Controlled Modification of Dynamically-Determined Object Attributes issue in Drupal ECA: Event - Condition - Action, which can lead to Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4. Users of Drupal ECA: Event - Condition - Action should assess and potentially u [truncated]
The Siteimprove Analytics module for Drupal is vulnerable to Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. This issue affects Siteimprove Analytics versions from 0.0.0 to 2.0.1. The CVE record was published on 2026-07-10T22:16:40.923Z and has not been modified since then. Users of Drupal Siteimprove Analytics versions from 0.0.0 to 2.0.1 should review and a [truncated]
A SQL Injection vulnerability was found in Drupal Location Selector. This issue affects Location Selector versions from 0.0.0 to 1.3.0. The vulnerability is classified as CWE-89, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'). Users of Drupal Location Selector versions from 0.0.0 to 1.3.0 should be aware of this SQL Injection vulnerability.
A Cross-Site Request Forgery (CSRF) vulnerability was found in Drupal Ray Enterprise Translation. The issue affects versions from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, and from 11.0.0 to 11.0.4. This vulnerability could allow attackers to perform unauthorized actions on behalf of users, potentially leading to security breaches. Users should assess their exposure and apply patches or updates provided by the [truncated]
CVE-2026-15079 is an Improper Restriction of Excessive Authentication Attempts vulnerability in the Drupal Login Disable module, which allows for Brute Force attacks. The issue affects Login Disable versions from 0.0.0 to 2.1.4. This vulnerability has a medium defensive priority, and users of affected versions should be aware of this vulnerability and take necessary precautions to prevent brute force attacks.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:40.523Z and has not been modified since then. This Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. Affected versions are from 0.0.0 to 2.4.0. Users of Drupal Tealium iQ Tag Management s [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in Drupal Salesforce Suite, affecting versions from 0.0.0 to 5.1.3. This issue allows for Cross Site Request Forgery. The vulnerability is identified as CVE-2026-13243 and is caused by a lack of proper validation of user requests, allowing an attacker to trick users into performing unintended actions. Users should review the official advisory and ap [truncated]
A SQL Injection vulnerability was found in Drupal Geolocation Field, affecting versions from 0.0.0 to 3.15.0. This issue is due to improper neutralization of special elements used in an SQL command. The vulnerability allows for SQL Injection attacks. Users of Drupal Geolocation Field should be aware of this vulnerability and take necessary actions to protect their installations. High priority should be gi [truncated]
A Missing Authorization vulnerability was reported in Drupal Paragraphs, which could allow Forceful Browsing. This issue affects Paragraphs versions from 0.0.0 to 1.21.0. The vulnerability has been identified as CVE-2026-13241. Users of Drupal Paragraphs versions from 0.0.0 to 1.21.0 should verify their installations and update to a patched version if necessary. The CVE record was published on 2026-07-10T [truncated]
A Missing Authorization vulnerability was reported in Drupal Paragraphs, which could allow Forceful Browsing. This issue affects Paragraphs versions from 0.0.0 to 1.21.0. The vulnerability, identified as CVE-2026-13240, involves a Missing Authorization issue within the Drupal Paragraphs module. This could potentially enable attackers to perform Forceful Browsing. Users are advised to update to a version b [truncated]
A Missing Authorization vulnerability exists in Drupal WissKI, potentially allowing Forceful Browsing. The issue affects WissKI versions from 0.0.0 to 4.2.0. This vulnerability could allow an attacker to access unauthorized areas of the system, potentially leading to data exposure or system compromise. Users of Drupal WissKI should review their current version and be aware of the potential risks associate [truncated]
CVE-2026-13238 is an Incorrect Authorization vulnerability in Drupal Commerce Realex, allowing for Forceful Browsing. The issue affects Commerce Realex versions from 0.0.0 to 3.0.2. Users of affected versions should apply patches or mitigations. The vulnerability has a medium defensive priority. This issue was confirmed by official CVE and NVD records. Defenders should verify affected scope and severity b [truncated]
CVE-2026-13237 is an Incorrect Authorization vulnerability in Drupal AI Agents that allows Forceful Browsing. The issue affects AI Agents versions from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, and from 1.3.0 to 1.3.1. This vulnerability could allow attackers to access unauthorized areas of the system, potentially leading to data breaches or system compromise. Users of Drupal AI Agents should be aware of this [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:39.700Z and has not been modified since then. This Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing, affecting versions from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, and from 1.3.0 to 1.3.1. Users of affected versions should be aware of this vulnerability and tak [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:39.597Z and has not been modified since then. This Missing Authorization vulnerability in Drupal AI allows Forceful Browsing, affecting versions from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, and from 1.4.0 to 1.4.3. Users of these versions should be aware of the potential impact and take neces [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:39.500Z and has not been modified since then. This Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability affects Drupal AI (Artificial Intelligence) versions from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, and from 1.4.0 to 1.4.3. The vulnerability coul [truncated]
CVE-2026-13233 is a Server-Side Request Forgery (SSRF) vulnerability in the Drupal OpenAI Provider. This issue affects OpenAI Provider versions from 0.0.0 to 1.1.1 and from 1.2.0 to 1.2.2. The CVE record was published on 2026-07-10T22:16:39.397Z and has not been modified since then. The vulnerability allows attackers to make unauthorized requests on behalf of the server, potentially leading to security br [truncated]
CVE-2026-13232 is an Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) that allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions from 0.0.0 to 2.8.0. The vulnerability has been publicly disclosed and may be actively exploited. Users of affected versions should review and apply necessary updates to mitigate potenti [truncated]
The CVE record for CVE-2026-13231 was published on 2026-07-10T22:16:39.187Z. The vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Drupal Advanced Content Feedback (admin_feedback) module, affecting versions from 0.0.0 to 2.8.0. Users should assess and apply patches or mitigations. The debrief aims to provide an executive overview of the vulnerability, its impact, and the context in which [truncated]
The CVE-2026-12535 vulnerability is an Improperly Controlled Modification of Dynamically-Determined Object Attributes issue in Drupal Formatter Field, which allows Object Injection. This issue affects Formatter Field versions from 0.0.0 to 2.0.0. The CVE record was published on 2026-07-10T22:16:39.077Z and has not been modified since then. Affected Drupal users and administrators should review and apply p [truncated]
A Missing Authorization vulnerability was reported in Drupal Examples for Developers, allowing for Forceful Browsing. The issue affects Examples for Developers versions from 0.0.0 to 4.0.6. This vulnerability has a significant impact on users of Drupal Examples for Developers, as it could allow attackers to access unauthorized resources. Users should be aware of this vulnerability and take necessary actio [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T22:16:38.873Z and has not been modified since then. This Stored Cross-site Scripting (XSS) vulnerability affects Drupal Tagify versions from 0.0.0 to 1.2.52. Users of affected versions should review and apply patches or mitigations. The vulnerability is classified as Improper Neutralization of In [truncated]
The CVE-2026-10770 vulnerability is classified as Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). It affects Drupal Anti-Spam by CleanTalk plugin versions from 0.0.0 to 9.7.1, allowing attackers to inject malicious scripts into web pages. Users of Drupal Anti-Spam by CleanTalk should review and apply the necessary patches to prevent Reflected XSS atta [truncated]
CVE-2026-10769 is a Stored XSS vulnerability in Drupal Commerce Core versions 3.3.0 to 3.3.6. This Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Users of affected versions should verify their deployments and apply patches or updates t [truncated]
A Missing Authorization vulnerability was reported in Drupal LocalGov Workflows, which could allow Forceful Browsing. The issue affects LocalGov Workflows versions from 0.0.0 to 1.6.0. Evidence is limited; verifying the vulnerability's scope and affected versions requires further review of primary official records. Users should consult the official CVE record and NVD detail for more information. The vulne [truncated]
CVE-2026-9726 is an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal AlternativeCommerce (Basket). The issue allows Object Injection and affects versions from 0.0.0 to 2.1.17. This CVE record was published on 2026-07-10T21:17:00.737Z and has not been modified since then. Users of Drupal AlternativeCommerce (Basket) should review their inventory and app [truncated]
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
A privilege escalation vulnerability exists in the Drupal SAML SSO - Service Provider module. The flaw stems from an improper check for unusual or exceptional conditions (CWE-754), allowing attackers to escalate privileges. Affected versions span from 0.0.0 through 3.1.3; version 3.1.4 contains the fix. The vulnerability was disclosed via official Drupal security advisory SA-CONTRIB-2026-031 on 2026-05-28 [truncated]
CVE-2026-9082 is a SQL injection issue in Drupal core recorded by NVD on 2026-05-20. The NVD entry rates it CVSS 6.5 (Medium) and lists network access, no privileges, no user interaction, and low attack complexity. Drupal’s referenced advisory identifies affected core release lines and fixed versions, so administrators should treat this as a patch-priority issue for exposed Drupal installations.
CVE-2026-4929 is a medium-severity cross-site scripting issue in Simple Hierarchical Select (SHS) for Drupal 7. The problem comes from improper output escaping of term-derived text, which can be rendered unsafely in affected output paths. The confirmed impacted code paths in the source corpus are the field formatter output path (shs_field_formatter_view) and the term-tree child-term data generation path ( [truncated]