ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76782
+1 in the same advisory: …76759
Cross-site scripting (XSS) in Drupal Screenshot module

CVE-2026-76782 is a cross-site scripting (XSS) flaw (CWE-79) in the Screenshot module for Drupal. The CVSS vector (AV:N/AC:H/PR:H/UI:R/S:C) indicates the attack occurs over a network, requires high attack complexity, requires the attacker to hold elevated (admin-level) privileges, and requires user interaction - consistent with a privileged user's injected script executing when another user, likely another privileged user, loads the affected page, with the attack crossing a security boundary (scope changed). A successful attacker could execute script in a victim's browser, potentially stealing session data or performing actions with that user's privileges. The advisory lists all versions of Screenshot (*.*) as affected and does not identify a fixed release in the available data. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.

Do: Monitor the Screenshot module's project page on Drupal.org and the Drupal Security Team advisories for a patched release, and update as soon as a fixed version is published; if the module is not essential, disable or uninstall it until a fix ships. Because exploitation requires admin-level privileges and user interaction, review which accounts hold administrative roles and remove unnecessary privileged access as an interim mitigation.

7.3<1%
  • Drupal (contributed module) Screenshot all versions (*.*); no fixed version specified in the available data
nichelikely low hundreds to low thousands of Drupal sites (niche contributed module; no install-count data provided)
CVE-2026-73475
Incorrect Authorization (Forceful Browsing) in Drupal Commerce PayPal

Commerce PayPal, the PayPal payment-gateway integration module for Drupal Commerce maintained by Centarro, contains an incorrect authorization flaw (CWE-863) that Drupal classifies as Forceful Browsing. Because the module fails to correctly enforce its access checks, an unauthenticated remote attacker can request protected routes or endpoints handled by the module and reach content or functionality they should not be able to access; the CVSS vector (network vector, no privileges, no user interaction, high confidentiality and integrity impact, no availability impact) indicates the attacker can both read sensitive data and modify data or state. Every published version of the module is affected, since both the 1.x line through 1.12.0 and the 2.x line through 2.1.3 fall within the affected ranges, so any Drupal site running Commerce PayPal is exposed. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, so no exploitation in the wild has been confirmed.

Do: Update Commerce PayPal to the first release published after 1.12.0 on the 1.x branch or after 2.1.3 on the 2.x branch, distributed via drupal.org. Until patched, review web-server logs for unauthenticated requests to the module's routes and audit recent PayPal orders and transactions for unauthorized access or changes. Take care that any network-level mitigation does not block PayPal's server-to-server callbacks (webhooks/IPN), which must remain publicly reachable.

9.1<1%
  • Centarro Commerce PayPal 0.0.0 through 1.12.0 (entire 1.x line up to and including 1.12.0)
  • Centarro Commerce PayPal 2.0.0 through 2.1.3 (entire 2.x line up to and including 2.1.3)
large≈10,000+ Drupal sites
CVE-2026-18985
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

NVD description · AI analysis pending
8.1<1%
  • Drupal
CVE-2026-18259
Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force.

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

NVD description · AI analysis pending
7.5<1%
  • Drupal
CVE-2026-16645
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing.

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.

NVD description · AI analysis pending
9.1<1%
  • Drupal
CVE-2026-16644
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

NVD description · AI analysis pending
9.1<1%
  • Drupal
CVE-2026-16641
Vulnerability in Drupal Commerce Elavon.

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

NVD description · AI analysis pending
9.8<1%
  • Drupal
CVE-2026-16639
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

NVD description · AI analysis pending
9.8<1%
  • Drupal
CVE-2026-15089
Vulnerability in Drupal Commerce guest registration.

Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.

NVD description · AI analysis pending
9.1<1%
  • Drupal
CVE-2026-11913
vulnerability in Drupal Mother May I allows .

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

NVD description · AI analysis pending
9.8<1%
  • Drupal
CVE-2026-55810
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection.

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

NVD description · AI analysis pending
8.1<1%
  • plotly plotly.js graphing
CVE-2026-55809
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection.

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.

NVD description · AI analysis pending
8.1<1%
  • flag attendance field project flag attendance field
CVE-2026-15081
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.

NVD description · AI analysis pending
7.4<1%
  • handkerchief location selector
CVE-2026-13244
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection.

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.

NVD description · AI analysis pending
8.1<1%
  • dakku tealium iq tag management
CVE-2026-12535
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection.

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

NVD description · AI analysis pending
9.8<1%
  • zroger formatter field
CVE-2026-10768
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

NVD description · AI analysis pending
9.82%
  • localgovdrupal localgov workflows
CVE-2026-9726
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injecti

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.

NVD description · AI analysis pending
9.8<1%
  • alternativecommerce alternativecommerce