Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities BSI Germany

[NEU] [mittel] Drupal Erweiterungen: Mehrere Schwachstellen

Multiple vulnerabilities in several Drupal extensions allow a remote attacker to manipulate or disclose data and conduct Cross-Site Scripting attacks. The CVSS Base Score for these issues is 7.2 (High). Affected extensions and versions include Drupal LocalGov Workflows before 1.6.0, TacJS before 6.8, Commerce Core before 3.3.6, and Anti-Spam by CleanTalk before 9.7.1. Mitigations are available, and administrators should upgrade to the specified fixed versions or apply the provided workarounds.
Read Full Article →

[WID-SEC-2026-1799] Drupal Erweiterungen: Mehrere Schwachstellen CVSS Base Score 7.2 (hoch) CVSS Temporal Score 6.3 (mittel) Remoteangriff ja Datum 04.06.2026 Stand 05.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 04.06.2026 Open Source Drupal LocalGov Workflows <1.6.0 Open Source Drupal TacJS <6.8 Open Source Drupal Commerce Core <3.3.6 Open Source Drupal Anti-Spam by CleanTalk <9.7.1 Angriff Angriff Ein entfernter Angreifer kann mehrere Schwachstellen in verschiedenen Drupal Erweiterungen ausnutzen, um Daten zu manipulieren oder offenzulegen, sowie um Cross-Site Scripting Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article