Title |
Severity |
Exploit |
Date |
Affected Version |
CVE-2025-3057
|
Medium
|
|
Apr 1, 2025
|
>= 8.0.0 < 10.3.13
>= 10.4.0 < 10.4.3
>= 11.0.0 < 11.0.12
>= 11.1.0 < 11.1.3
|
CVE-2025-31674
|
Medium
|
|
Apr 1, 2025
|
>= 8.0.0 < 10.3.13
>= 10.4.0 < 10.4.3
>= 11.0.0 < 11.0.12
>= 11.1.0 < 11.1.3
|
CVE-2025-31675
|
Low
|
|
Apr 1, 2025
|
>= 8.0.0 < 10.3.14
>= 10.4.0 < 10.4.5
>= 11.0.0 < 11.0.13
>= 11.1.0 < 11.1.5
|
CVE-2025-31673
|
Medium
|
|
Apr 1, 2025
|
>= 8.0.0 < 10.3.13
>= 10.4.0 < 10.4.3
>= 11.0.0 < 11.0.12
>= 11.1.0 < 11.1.3
|
Drupal core Cross-Site Scripting (XSS) vulnerabilities
|
Medium
|
|
May 15, 2024
|
>= 8.0.0 < 8.9.18
>= 9.1.0 < 9.1.12
>= 9.2.0 < 9.2.4
|
Drupal core Arbitrary PHP code execution
|
High
|
|
May 15, 2024
|
>= 7.0.0 < 7.75
>= 8.0.0 < 8.8.12
>= 8.9.0 < 8.9.10
>= 9.0.0 < 9.0.9
|
Drupal core Open Redirect vulnerability
|
Medium
|
|
May 15, 2024
|
>= 7.0.0 < 7.70
|
Drupal core uses a vulnerable Third-party library CKEditor
|
Medium
|
|
May 15, 2024
|
>= 8.0.0 < 8.7.12
>= 8.8.0 < 8.8.4
|
Drupal core Multiple vulnerabilities due to the use of the third-party library Archive_Tar
|
High
|
|
May 15, 2024
|
>= 7.0.0 < 7.69
>= 8.0.0 < 8.7.11
>= 8.8.0 < 8.8.1
|
Drupal core Access bypass
|
Medium
|
|
May 15, 2024
|
>= 8.0.0 < 8.7.11
>= 8.8.0 < 8.8.1
|