[WID-SEC-2026-2080] Drupal: Mehrere Schwachstellen CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff ja Datum 24.06.2026 Stand 25.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 24.06.2026 Open Source Drupal Advanced Content Feedback <2.8.0 Open Source Drupal OpenAI Provider <1.1.1 Open Source Drupal OpenAI Provider <1.2.2 Open Source Drupal AI <1.2.17 Open Source Drupal AI <1.3.8 Open Source Drupal AI <1.4.3 Open Source Drupal AI Agents <1.1.4 Open Source Drupal AI Agents <1.2.5 Open Source Drupal AI Agents <1.3.1 Open Source Drupal Commerce Realex / Global Payments <3.0.2 Open Source Drupal WissKI <4.2.0 Open Source Drupal Paragraphs <1.21.0 Open Source Drupal Geolocation Field <3.15.0 Open Source Drupal Salesforce Suite <5.1.3 Open Source Drupal Tealium iQ Tag Management Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen, um Informationen offenzulegen, um einen SQL-Injection Angriff durchzuführen, und um Daten zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in Drupal, including Cross-Site Scripting, SQL Injection, and data manipulation flaws, can be exploited remotely. The CVSS Base Score for these issues is 7.3 (High). Affected systems include Drupal Advanced Content Feedback versions prior to 2.8.0, OpenAI Provider prior to 1.1.1 and 1.2.2, AI prior to 1.2.17, 1.3.8, and 1.4.3, AI Agents prior to 1.1.4, 1.2.5, and 1.3.1, and several other specific modules listed in the advisory.