Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Joãl Pittet

#18936of 56,330
15.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-76591
5.3
2026-08-12
Drupal · Quick Tabs · CVE-2026-73477
**Name of the Vulnerable Software and Affected Versions** Drupal Quick Tabs versions 0.0.0 through 4.3.1 **Description** An incorrect authorization issue allows forceful browsing. The module fails to correctly enforce access when rendering node and block tabs by treating neutral access results as grants for node tabs and block plugins. Additionally, no access check is performed for reusable custom blocks. This allows users without proper permissions to view restricted content, such as unpublished nodes or unpublished reusable custom blocks. The risk is limited because the content exposed is pre-selected by a user with the `administer quicktabs` permission during configuration. **Recommendations** Update Drupal Quick Tabs to a version later than 4.3.1.
PT-2026-40839
9.8
2026-05-13
Drupal · Date Ical · CVE-2026-8495
**Name of the Vulnerable Software and Affected Versions** Date iCal versions 0.0.0 through 4.0.14 **Description** A missing authorization issue in the Date iCal module, which exports entity date fields as iCal feeds, allows forceful browsing. The module fails to sufficiently check entity or field access and does not properly sanitize user inputs during the generation of iCal feeds. These routes are accessible to all anonymous users without requiring any configuration. **Recommendations** Update to version 4.0.15.