ZeroHour

Vulnerabilities

89 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81269
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing.

Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.

NVD description · AI analysis pending
5.3<1%
  • data field project data field
CVE-2026-81205
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Inj

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

NVD description · AI analysis pending
5.3<1%
  • Drupal
CVE-2026-81201
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.

NVD description · AI analysis pending
6.1<1%
  • Drupal
CVE-2026-81168
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

NVD description · AI analysis pending
3.7<1%
  • captcha protected page project captcha protected page
CVE-2026-81167
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.

NVD description · AI analysis pending
4.8<1%
  • address suggestion project address suggestion
CVE-2026-81166
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing.

Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.

NVD description · AI analysis pending
5.3<1%
  • Drupal
CVE-2026-81165
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

NVD description · AI analysis pending
5.3<1%
  • Drupal
CVE-2026-81164
Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing.

Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.

NVD description · AI analysis pending
5.4<1%
  • Drupal
CVE-2026-81162
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder:

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

NVD description · AI analysis pending
5.3<1%
  • dxpr builder project dxpr builder
CVE-2026-81161
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation.

Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.

NVD description · AI analysis pending
3.3<1%
  • Drupal
CVE-2026-81160
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.

NVD description · AI analysis pending
6.1<1%
  • Drupal
CVE-2026-81159
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force.

Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.

NVD description · AI analysis pending
3.7<1%
  • Drupal
CVE-2026-81158
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

NVD description · AI analysis pending
5.3<1%
  • Drupal
CVE-2026-76782
+1 in the same advisory: …76759
Cross-site scripting (XSS) in Drupal Screenshot module

CVE-2026-76782 is a cross-site scripting (XSS) flaw (CWE-79) in the Screenshot module for Drupal. The CVSS vector (AV:N/AC:H/PR:H/UI:R/S:C) indicates the attack occurs over a network, requires high attack complexity, requires the attacker to hold elevated (admin-level) privileges, and requires user interaction - consistent with a privileged user's injected script executing when another user, likely another privileged user, loads the affected page, with the attack crossing a security boundary (scope changed). A successful attacker could execute script in a victim's browser, potentially stealing session data or performing actions with that user's privileges. The advisory lists all versions of Screenshot (*.*) as affected and does not identify a fixed release in the available data. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.

Do: Monitor the Screenshot module's project page on Drupal.org and the Drupal Security Team advisories for a patched release, and update as soon as a fixed version is published; if the module is not essential, disable or uninstall it until a fix ships. Because exploitation requires admin-level privileges and user interaction, review which accounts hold administrative roles and remove unnecessary privileged access as an interim mitigation.

7.3<1%
  • Drupal (contributed module) Screenshot all versions (*.*); no fixed version specified in the available data
nichelikely low hundreds to low thousands of Drupal sites (niche contributed module; no install-count data provided)
CVE-2026-76758
Vulnerability in Drupal Link content parser.

Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.

NVD description · AI analysis pending
5.9<1%
  • Drupal
CVE-2026-76757
+2 in the same advisory: …76756 …76755
Vulnerability in Drupal Gammu SMS Daemon.

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

NVD description · AI analysis pending
5.9<1%
  • Drupal
CVE-2026-73478
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

NVD description · AI analysis pending
5.3<1%
  • Drupal
CVE-2026-73477
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.

NVD description · AI analysis pending
5.3<1%
  • Drupal
CVE-2026-73476
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation.

Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.

NVD description · AI analysis pending
5.4<1%
  • external authentication project external authentication
CVE-2026-73475
Incorrect Authorization (Forceful Browsing) in Drupal Commerce PayPal

Commerce PayPal, the PayPal payment-gateway integration module for Drupal Commerce maintained by Centarro, contains an incorrect authorization flaw (CWE-863) that Drupal classifies as Forceful Browsing. Because the module fails to correctly enforce its access checks, an unauthenticated remote attacker can request protected routes or endpoints handled by the module and reach content or functionality they should not be able to access; the CVSS vector (network vector, no privileges, no user interaction, high confidentiality and integrity impact, no availability impact) indicates the attacker can both read sensitive data and modify data or state. Every published version of the module is affected, since both the 1.x line through 1.12.0 and the 2.x line through 2.1.3 fall within the affected ranges, so any Drupal site running Commerce PayPal is exposed. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, so no exploitation in the wild has been confirmed.

Do: Update Commerce PayPal to the first release published after 1.12.0 on the 1.x branch or after 2.1.3 on the 2.x branch, distributed via drupal.org. Until patched, review web-server logs for unauthenticated requests to the module's routes and audit recent PayPal orders and transactions for unauthorized access or changes. Take care that any network-level mitigation does not block PayPal's server-to-server callbacks (webhooks/IPN), which must remain publicly reachable.

9.1<1%
  • Centarro Commerce PayPal 0.0.0 through 1.12.0 (entire 1.x line up to and including 1.12.0)
  • Centarro Commerce PayPal 2.0.0 through 2.1.3 (entire 2.x line up to and including 2.1.3)
large≈10,000+ Drupal sites
CVE-2026-73474
Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery.

Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.

NVD description · AI analysis pending
5.3<1%
  • entity share websub project entity share websub
CVE-2026-18986
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.

NVD description · AI analysis pending
4.8<1%
  • entity browser project entity browser
CVE-2026-16647
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

NVD description · AI analysis pending
4.1<1%
  • zyxware disable login page
CVE-2026-55805
+1 in the same advisory: …15917
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

NVD description · AI analysis pending
5.4
group max
<1%
  • Drupal
CVE-2026-18985
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

NVD description · AI analysis pending
8.1<1%
  • Drupal
CVE-2026-18261
Vulnerability in Drupal Powerful Surveys.

Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

NVD description · AI analysis pending
5.7<1%
  • Drupal
CVE-2026-18260
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force.

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

NVD description · AI analysis pending
5.7<1%
  • Drupal
CVE-2026-18259
Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force.

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

NVD description · AI analysis pending
7.5<1%
  • Drupal
CVE-2026-16646
Vulnerability in Drupal PanKM.

Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

NVD description · AI analysis pending
5.7<1%
  • Drupal
CVE-2026-16645
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing.

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.

NVD description · AI analysis pending
9.1<1%
  • Drupal
CVE-2026-16644
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing.

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

NVD description · AI analysis pending
9.1<1%
  • Drupal
CVE-2026-16643
Vulnerability in Drupal Lunr exposed filters.

Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

NVD description · AI analysis pending
5.7<1%
  • Drupal
CVE-2026-16642
Vulnerability in Drupal Email Login OTP.

Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

NVD description · AI analysis pending
5.7<1%
  • Drupal
CVE-2026-16641
Vulnerability in Drupal Commerce Elavon.

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

NVD description · AI analysis pending
9.8<1%
  • Drupal
CVE-2026-16640
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.

NVD description · AI analysis pending
6.1<1%
  • Drupal
CVE-2026-16639
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

NVD description · AI analysis pending
9.8<1%
  • Drupal
CVE-2026-16638
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.

NVD description · AI analysis pending
6.1<1%
  • Drupal
CVE-2026-15916
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.

Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

NVD description · AI analysis pending
4.2<1%
  • Drupal
CVE-2026-15088
Vulnerability in Drupal Development Environment.

Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.

NVD description · AI analysis pending
5.7<1%
  • Drupal
CVE-2026-15089
Vulnerability in Drupal Commerce guest registration.

Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.

NVD description · AI analysis pending
9.1<1%
  • Drupal
CVE-2026-15087
vulnerability in Drupal Clean RESTful allows .

vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

NVD description · AI analysis pending
5.9<1%
  • Drupal
CVE-2026-15086
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows .

vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.

NVD description · AI analysis pending
5.9<1%
  • Drupal
CVE-2026-11915
vulnerability in Drupal Brute force attack protection allows .

vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

NVD description · AI analysis pending
5.9<1%
  • Drupal
CVE-2026-11914
vulnerability in Drupal Composer allows .

vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

NVD description · AI analysis pending
5.9<1%
  • Drupal
CVE-2026-11913
vulnerability in Drupal Mother May I allows .

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

NVD description · AI analysis pending
9.8<1%
  • Drupal
CVE-2026-58591
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

NVD description · AI analysis pending
5.4<1%
  • colorbox project colorbox