Výsledky hledání

výrobce: Drupal× v celém archivu zrušit filtry

4 karet z 4 položek CZ · EN/orig

2

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal. Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target…

Drupal CKEditor FI

tg: zranitelnost

· NCSC-FI · Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

1

Multiple important vulnerabilities in Drupal

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-16639, CVE-2026-16646, CVE-2026-15917, CVE-2026-15916, CVE-2026-16640, CVE-2026-16638, CVE-2026-55805, CVE-2026-18261, CVE-2026-18260, CVE-2026-18259, CVE-2026-16645, CVE-2026-16644, CVE-2026-16643, CVE-2026-16642, CVE-2026-16641, CVE-2026-15088, CVE-2026-18985, Summary: CVE-2026-16639 : Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 CVE-2026-16646 :…

EPSS 0.00 CVSS 9.8 CVE-2026-15088 CVE-2026-15916 CVE-2026-15917 CVE-2026-16638 CVE-2026-16639 CVE-2026-16640 CVE-2026-16641 CVE-2026-16642 CVE-2026-16643 CVE-2026-16644 CVE-2026-16645 CVE-2026-16646 CVE-2026-18259 CVE-2026-18260 CVE-2026-18261 CVE-2026-18985 CVE-2026-55805 Drupal FI

· NCSC-FI · Multiple important vulnerabilities in Drupal

1

Kritische Sicherheitslücke in Drupal Core - Updates verfügbar

20. Mai 2026 Beschreibung In Drupal Core existiert eine SQL-Injection-Schwachstelle in der Datenbank-Abstraktions-API. Speziell gestaltete Anfragen können zu beliebigen SQL-Injections führen. Die Schwachstelle ist ausschließlich für Drupal-Installationen relevant, die PostgreSQL als Datenbank einsetzen, und kann ohne Authentifizierung durch anonyme Benutzer:innen ausgenutzt werden. Zusätzlich zur SQL-Injection enthalten die Drupal-Releases für die unterstützten Versionszweige (11.3, 11.2, 10.6…

KEV ✓ EPSS 0.90 CVE-2026-9082 Drupal AT

· CERT.at · Kritische Sicherheitslücke in Drupal Core - Updates verfügbar