Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Gaus Surahman

#22821of 56,334
11.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-82364
6.1
2026-08-26
Drupal · Slick Carousel · CVE-2026-81160
**Name of the Vulnerable Software and Affected Versions** Drupal Slick Carousel versions 0.0.0 through 2.1.0 **Description** Improper neutralization of input during web page generation in the Slick UI sub-module allows for Stored Cross-site Scripting (XSS). The issue occurs because the module does not sufficiently validate user input within Slick option sets that contain HTML for carousel buttons. **Recommendations** Update Drupal Slick Carousel to version 8.x-2.1 or later.
PT-2026-82368
5.3
2026-08-26
Drupal · Blazy · CVE-2026-81165
**Name of the Vulnerable Software and Affected Versions** Drupal Blazy versions 0.0.0 through 3.0.18 **Description** An incorrect authorization issue allows forceful browsing. The module enables users to display a field of a target entity using a Blazy Filter plugin shortcode. Because the module does not consistently check entity view access, a user with access to a Blazy-enabled text format can render a field from an entity they are not permitted to view. This is limited to fields that the shortcode is capable of rendering. **Recommendations** Update Drupal Blazy to a version later than 3.0.18.