Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bálint Nagy

#19227of 53,633
13.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-21193
6.1
2025-05-14
Drupal · Drupal Iframe Remove Filter · CVE-2025-47705
Name of the Vulnerable Software and Affected Versions: Drupal IFrame Remove Filter versions 0.0.0 through 2.0.4 Description: The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows an attacker to perform Cross-Site Scripting attacks. Recommendations: For versions 0.0.0 through 2.0.4, update to version 2.0.5 or later to resolve the issue.
PT-2024-10347
7.8
2024-05-22
Drupal · Email Contact · CVE-2024-13256
**Name of the Vulnerable Software and Affected Versions** Email Contact versions 0.0.0 through 2.0.4 **Description** The issue is related to insufficient granularity of access control in the Email Contact module for Drupal, allowing forceful browsing. This can be exploited by a remote attacker to bypass security restrictions. **Recommendations** For versions 0.0.0 through 2.0.4, update to a version newer than 2.0.4 to resolve the issue. As a temporary workaround, consider restricting access to the Email Contact module to minimize the risk of exploitation.