
CVE-2025-3062 – Drupal Admin LTE theme - Critical - Unsupported - SA-CONTRIB-2025-010
https://notcve.org/view.php?id=CVE-2025-3062
31 Mar 2025 — Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*. • https://www.drupal.org/sa-contrib-2025-010 • CWE-287: Improper Authentication •

CVE-2025-31675 – Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004
https://notcve.org/view.php?id=CVE-2025-31675
31 Mar 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5. • https://www.drupal.org/sa-core-2025-004 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-31674 – Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003
https://notcve.org/view.php?id=CVE-2025-31674
31 Mar 2025 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3. • https://www.drupal.org/sa-core-2025-003 • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes •

CVE-2025-31673 – Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002
https://notcve.org/view.php?id=CVE-2025-31673
31 Mar 2025 — Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3. • https://www.drupal.org/sa-core-2025-002 • CWE-863: Incorrect Authorization •

CVE-2025-3057 – Drupal core - Critical - Cross site scripting - SA-CORE-2025-001
https://notcve.org/view.php?id=CVE-2025-3057
31 Mar 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3. • https://www.drupal.org/sa-core-2025-001 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-13310 – Git Utilities for Drupal - Critical - Unsupported - SA-CONTRIB-2024-074
https://notcve.org/view.php?id=CVE-2024-13310
09 Jan 2025 — Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*. • https://www.drupal.org/sa-contrib-2024-074 •

CVE-2024-13258 – Drupal REST & JSON API Authentication - Moderately critical - Access bypass - SA-CONTRIB-2024-022
https://notcve.org/view.php?id=CVE-2024-13258
09 Jan 2025 — Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13. • https://www.drupal.org/sa-contrib-2024-022 • CWE-863: Incorrect Authorization •

CVE-2024-13250 – Drupal Symfony Mailer Lite - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-014
https://notcve.org/view.php?id=CVE-2024-13250
09 Jan 2025 — Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6. • https://www.drupal.org/sa-contrib-2024-014 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2024-55638 – Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008
https://notcve.org/view.php?id=CVE-2024-55638
09 Dec 2024 — Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the... • https://www.drupal.org/sa-core-2024-008 • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes •

CVE-2024-55637 – Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007
https://notcve.org/view.php?id=CVE-2024-55637
09 Dec 2024 — Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exist... • https://www.drupal.org/sa-core-2024-007 • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes •