Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nigel Cunningham

#22675of 56,330
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-34625
6.1
2026-04-22
Drupal · Obfuscate · CVE-2026-6871
**Name of the Vulnerable Software and Affected Versions** Obfuscate versions 0.0.0 through 2.0.1 **Description** Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS). The module, which obfuscates email addresses in content, fails to sufficiently sanitize user input via the Twig filter. This issue specifically affects sites utilizing ROT13 encoding (a simple substitution cipher that replaces a letter with the 13th letter after it in the alphabet) in scenarios where an attacker can provide content filtered by the module's Twig filter. **Recommendations** Update to version 2.0.2.
PT-2025-14555
5.4
2025-04-02
Obfuscate · Obfuscate · CVE-2025-3130
**Name of the Vulnerable Software and Affected Versions** Obfuscate versions 0.0.0 through 2.0.0 **Description** The issue is related to improper neutralization of input during web page generation, which allows for Stored XSS. This means that an attacker can inject malicious scripts into the website, potentially affecting users who access the compromised page. **Recommendations** For Obfuscate versions 0.0.0 through 2.0.0, update to version 2.0.1 or later to resolve the issue.