Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Douglas Groene

#22824of 56,330
11.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-82362
5.3
2026-08-26
Drupal · Entity Api · CVE-2026-81158
**Name of the Vulnerable Software and Affected Versions** Entity API versions 0.0.0 through 1.8.0 **Description** An incorrect authorization issue in the Entity API allows forceful browsing. The module fails to correctly apply access controls for JSON:API entity collection endpoints, leading to an information disclosure. This issue occurs when the JSON:API module is enabled alongside the Entity API module. **Recommendations** Update Entity API to a version later than 1.8.0. As a temporary mitigation, disable the JSON:API module to prevent the exploitation of the entity collection endpoints.
PT-2025-13836
6.1
2025-02-19
Drupal · Drupal · CVE-2025-3057
**Name of the Vulnerable Software and Affected Versions** Drupal core versions 8.0.0 through 10.3.12 Drupal core versions 10.4.0 through 10.4.2 Drupal core versions 11.0.0 through 11.0.11 Drupal core versions 11.1.0 through 11.1.2 **Description** The issue affects Drupal core, allowing Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation. **Recommendations** For versions 8.0.0 through 10.3.12, update to version 10.3.13 or later. For versions 10.4.0 through 10.4.2, update to version 10.4.3 or later. For versions 11.0.0 through 11.0.11, update to version 11.0.12 or later. For versions 11.1.0 through 11.1.2, update to version 11.1.3 or later.