Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Giuseppe

#19866of 56,329
14.4Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-63540
9.1
2026-07-22
Drupal · Webform Rest · CVE-2026-16644
**Name of the Vulnerable Software and Affected Versions** Drupal Webform REST versions 0.0.0 through 4.1.0 **Description** Incorrect authorization in the module allows forceful browsing. The module fails to sufficiently verify permissions for creating, viewing, and updating the parent webform when accessing REST endpoints. This issue requires the attacker to already possess permissions to use the REST resource. **Recommendations** Update Drupal Webform REST to a version later than 4.1.0.
PT-2024-10085
5.3
2024-12-04
Drupal · Download All Files · CVE-2024-13303
**Name of the Vulnerable Software and Affected Versions** Download All Files versions 0.0.0 through 2.0.1 **Description** The issue is related to a Missing Authorization vulnerability in the Download All Files module for the Drupal CMS, which allows for Forceful Browsing. This vulnerability can be exploited by a remote attacker to bypass security restrictions and perform a forceful browsing attack. **Recommendations** For versions 0.0.0 through 2.0.1, update to version 2.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Download All Files module to minimize the risk of exploitation.