Latest CVE Feed
-
4.8
MEDIUMCVE-2024-13305
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.... Read more
Affected Products : entity_form_steps- Published: Jan. 09, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
4.5
MEDIUMCVE-2024-13304
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.... Read more
Affected Products : minify_js- Published: Jan. 09, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2024-13303
Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.... Read more
Affected Products : download_all_files- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13302
Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.... Read more
Affected Products : pages_restriction_access- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-13301
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single... Read more
Affected Products : oauth_\&_openid_connect_single_sign-on- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.6
MEDIUMCVE-2024-13300
Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*.... Read more
Affected Products : print_anything- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
-
6.6
MEDIUMCVE-2024-13299
Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*.... Read more
Affected Products : megamenu_framework- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
-
4.8
MEDIUMCVE-2024-13298
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5.... Read more
Affected Products : tarte_au_citron- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.6
MEDIUMCVE-2024-13297
Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.... Read more
Affected Products : eloqua- Published: Jan. 09, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
6.6
MEDIUMCVE-2024-13296
Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.... Read more
Affected Products : mailjet- Published: Jan. 09, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
6.6
MEDIUMCVE-2024-13295
Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.... Read more
Affected Products : node_export- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-13294
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal POST File allows Cross-Site Scripting (XSS).This issue affects POST File: from 0.0.0 before 1.0.2.... Read more
Affected Products : post_file- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
3.1
LOWCVE-2024-13293
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.... Read more
Affected Products : post_file- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2024-13292
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip allows Cross-Site Scripting (XSS).This issue affects Tooltip: from 0.0.0 before 1.1.2.... Read more
Affected Products : tooltip- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2024-13291
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.... Read more
Affected Products : basic_http_authentication- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13290
Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.... Read more
Affected Products : ohdear_integration- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-13289
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.... Read more
Affected Products : cookiebot_\+_gtm- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-13288
Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.... Read more
Affected Products : monster_menus- Published: Jan. 09, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-56114
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to su... Read more
Affected Products : canlineapp- Published: Jan. 09, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-56113
Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Information Disclosure