[WID-SEC-2026-2181] Drupal Extensions: Mehrere Schwachstellen CVSS Base Score 6.4 (mittel) CVSS Temporal Score 5.6 (mittel) Remoteangriff ja Datum 01.07.2026 Stand 02.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 01.07.2026 Open Source Drupal Canvas <1.4.2 Open Source Drupal Canvas <1.5.2 Open Source Drupal Canvas <1.6.1 Open Source Drupal Canvas <1.7.1 Open Source Drupal FlowDrop <1.6.0 Open Source Drupal Colorbox <2.1.5 Open Source Drupal Colorbox <2.2.1 Angriff Angriff Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in several Drupal extensions allow an authenticated remote attacker to conduct cross-site scripting attacks, bypass security measures, and manipulate data. The CVSS base score for these issues is 6.4 (Medium). Affected versions include Drupal Canvas prior to 1.4.2, 1.5.2, 1.6.1, and 1.7.1; Drupal FlowDrop prior to 1.6.0; and Drupal Colorbox prior to 2.1.5 and 2.2.1.