Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities BSI Germany

[NEU] [hoch] Drupal Module: Mehrere Schwachstellen

Multiple critical vulnerabilities in several Drupal modules, including SQL Injection, security bypass, information disclosure, and Cross-Site Scripting, can be exploited remotely. The CVSS base score for these vulnerabilities is 9.8. Affected versions include Drupal Ray Enterprise Translation <11.0.4, <4.1.4, and <4.0.4; Login Disable <2.1.4; Location Selector <8.x-1.3; ECA <3.1.4, <3.0.12, and <2.1.20; UI Patterns <2.0.17; Siteimprove Analytics <2.0.1; AI SEO/GEO Analyzer <1.1.3; and the Raw Formatter [Meta Tag Formatter], Commerce guest registration, and Clean RESTful modules.
Read Full Article →

[WID-SEC-2026-2251] Drupal Module: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 08.07.2026 Stand 09.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden. Produkte 08.07.2026 Open Source Drupal Ray Enterprise Translation <11.0.4 Open Source Drupal Ray Enterprise Translation <4.1.4 Open Source Drupal Ray Enterprise Translation <4.0.4 Open Source Drupal Login Disable <2.1.4 Open Source Drupal Location Selector <8.x-1.3 Open Source Drupal ECA <3.1.4 Open Source Drupal ECA <3.0.12 Open Source Drupal ECA <2.1.20 Open Source Drupal UI Patterns <2.0.17 Open Source Drupal Siteimprove Analytics <2.0.1 Open Source Drupal AI SEO/GEO Analyzer <1.1.3 Open Source Drupal Raw Formatter [Meta Tag Formatter] Open Source Drupal Commerce guest registration Open Source Drupal Clean RESTful Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, umSQL-Injection-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Share this article