WID-SEC-W-2026-3554
Vulnerability from csaf_certbund - Published: 2026-09-23 22:00 - Updated: 2026-09-23 22:00Summary
Drupal Erweiterungen: Mehrere Schwachstellen
Severity
Hoch
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung: Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. Über zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden.
Angriff: Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.
Betroffene Betriebssysteme: - Linux
- Sonstiges
- UNIX
- Windows
Affected products
Known affected
19 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Open Source Drupal Project Browser <2.0.3
Open Source / Drupal
|
Project Browser <2.0.3 | ||
|
Open Source Drupal AI CKEditor <1.4.3
Open Source / Drupal
|
AI CKEditor <1.4.3 | ||
|
Open Source Drupal Cloud <7.0.1
Open Source / Drupal
|
Cloud <7.0.1 | ||
|
Open Source Drupal Webform REST <4.2.1
Open Source / Drupal
|
Webform REST <4.2.1 | ||
|
Open Source Drupal Editoria11y Accessibility Checker <3.0.9
Open Source / Drupal
|
Editoria11y Accessibility Checker <3.0.9 | ||
|
Open Source Drupal Editoria11y Accessibility Checker <2.2.23
Open Source / Drupal
|
Editoria11y Accessibility Checker <2.2.23 | ||
|
Open Source Drupal Project Browser <2.1.5
Open Source / Drupal
|
Project Browser <2.1.5 | ||
|
Open Source Drupal Mermaid Diagram Field <1.0.9
Open Source / Drupal
|
Mermaid Diagram Field <1.0.9 | ||
|
Open Source Drupal Smart Content <3.2.1
Open Source / Drupal
|
Smart Content <3.2.1 | ||
|
Open Source Drupal Commerce Decoupled Checkout <1.8.0
Open Source / Drupal
|
Commerce Decoupled Checkout <1.8.0 | ||
|
Open Source Drupal CSS Usage Analyzer <1.0.2
Open Source / Drupal
|
CSS Usage Analyzer <1.0.2 | ||
|
Open Source Drupal Combined image style <1.0.7
Open Source / Drupal
|
Combined image style <1.0.7 | ||
|
Open Source Drupal Tawk.to-Live chat application <3.0.4
Open Source / Drupal
|
Tawk.to-Live chat application <3.0.4 | ||
|
Open Source Drupal Webform <6.3.1
Open Source / Drupal
|
Webform <6.3.1 | ||
|
Open Source Drupal Stop administrator login <1.6
Open Source / Drupal
|
Stop administrator login <1.6 | ||
|
Open Source Drupal Webform <6.2.12
Open Source / Drupal
|
Webform <6.2.12 | ||
|
Open Source Drupal REST & JSON API Authentication <3.2.0
Open Source / Drupal
|
cpe:/a:drupal:drupal:est__json_api_authentication__3.2.0
|
— | |
|
Open Source Drupal CookieCuttr <2.0.3
Open Source / Drupal
|
CookieCuttr <2.0.3 | ||
|
Open Source Drupal Diba carousel slider <3.0.2
Open Source / Drupal
|
Diba carousel slider <3.0.2 |
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
Affected products
Known affected
19 products, the same list as for
CVE-2026-96355
References
39 references
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "Drupal ist ein freies Content-Management-System, basierend auf der Scriptsprache PHP und einer SQL-Datenbank. \u00dcber zahlreiche Extensions kann der Funktionsumfang der Core-Installation individuell erweitert werden.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen in Drupal ausnutzen, um beliebigen Programmcode auszuf\u00fchren, erweiterte Berechtigungen zu erlangen, Sicherheitsma\u00dfnahmen zu umgehen, Daten zu manipulieren und offenzulegen oder Cross-Site-Scripting-Angriffe durchzuf\u00fchren.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Linux\n- Sonstiges\n- UNIX\n- Windows",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3554 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3554.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3554 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-154 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-154"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-155 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-155"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-158 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-158"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-158 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-158-0"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-159 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-159"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-160 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-160"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-161 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-161"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-162 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-162"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-163 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-163"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-164 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-164"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-165 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-165"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-166 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-166"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-167 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-167"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-168 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-168"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-169 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-169"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-170 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-170"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-171 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-171"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-172 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-172"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-173 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-173"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-174 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-174"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-175 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-175"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-176 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-176"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-177 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-177"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-178 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-178"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-179 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-179"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-180 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-180"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-181 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-181"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-182 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-182"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-183 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-183"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-184 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-184"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-185 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-185"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-186 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-186"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-187 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-187"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-188 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-188"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-189 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-189"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-190 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-190"
},
{
"category": "external",
"summary": "Drupal Security Advisory sa-contrib-2026-191 vom 2026-09-23",
"url": "https://www.drupal.org/sa-contrib-2026-191"
}
],
"source_lang": "en-US",
"title": "Drupal Erweiterungen: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-09-23T22:00:00.000+00:00",
"generator": {
"date": "2026-09-24T11:54:26.191+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3554",
"initial_release_date": "2026-09-23T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-09-23T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
}
],
"status": "final",
"version": "1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Webform \u003c6.2.12",
"product": {
"name": "Open Source Drupal Webform \u003c6.2.12",
"product_id": "T060102"
}
},
{
"category": "product_version",
"name": "Webform 6.2.12",
"product": {
"name": "Open Source Drupal Webform 6.2.12",
"product_id": "T060102-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:webform__6.2.12"
}
}
},
{
"category": "product_version_range",
"name": "Webform \u003c6.3.1",
"product": {
"name": "Open Source Drupal Webform \u003c6.3.1",
"product_id": "T060103"
}
},
{
"category": "product_version",
"name": "Webform 6.3.1",
"product": {
"name": "Open Source Drupal Webform 6.3.1",
"product_id": "T060103-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:webform__6.3.1"
}
}
},
{
"category": "product_version_range",
"name": "Cloud \u003c7.0.1",
"product": {
"name": "Open Source Drupal Cloud \u003c7.0.1",
"product_id": "T060107"
}
},
{
"category": "product_version",
"name": "Cloud 7.0.1",
"product": {
"name": "Open Source Drupal Cloud 7.0.1",
"product_id": "T060107-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:cloud__7.0.1"
}
}
},
{
"category": "product_version_range",
"name": "Project Browser \u003c2.0.3",
"product": {
"name": "Open Source Drupal Project Browser \u003c2.0.3",
"product_id": "T060108"
}
},
{
"category": "product_version",
"name": "Project Browser 2.0.3",
"product": {
"name": "Open Source Drupal Project Browser 2.0.3",
"product_id": "T060108-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:project_browser__2.0.3"
}
}
},
{
"category": "product_version_range",
"name": "Project Browser \u003c2.1.5",
"product": {
"name": "Open Source Drupal Project Browser \u003c2.1.5",
"product_id": "T060109"
}
},
{
"category": "product_version",
"name": "Project Browser 2.1.5",
"product": {
"name": "Open Source Drupal Project Browser 2.1.5",
"product_id": "T060109-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:project_browser__2.1.5"
}
}
},
{
"category": "product_version_range",
"name": "Commerce Decoupled Checkout \u003c1.8.0",
"product": {
"name": "Open Source Drupal Commerce Decoupled Checkout \u003c1.8.0",
"product_id": "T060110"
}
},
{
"category": "product_version",
"name": "Commerce Decoupled Checkout 1.8.0",
"product": {
"name": "Open Source Drupal Commerce Decoupled Checkout 1.8.0",
"product_id": "T060110-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:commerce_decoupled_checkout__1.8.0"
}
}
},
{
"category": "product_version_range",
"name": "Mermaid Diagram Field \u003c1.0.9",
"product": {
"name": "Open Source Drupal Mermaid Diagram Field \u003c1.0.9",
"product_id": "T060111"
}
},
{
"category": "product_version",
"name": "Mermaid Diagram Field 1.0.9",
"product": {
"name": "Open Source Drupal Mermaid Diagram Field 1.0.9",
"product_id": "T060111-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:mermaid_diagram_field__1.0.9"
}
}
},
{
"category": "product_version_range",
"name": "CookieCuttr \u003c2.0.3",
"product": {
"name": "Open Source Drupal CookieCuttr \u003c2.0.3",
"product_id": "T060112"
}
},
{
"category": "product_version",
"name": "CookieCuttr 2.0.3",
"product": {
"name": "Open Source Drupal CookieCuttr 2.0.3",
"product_id": "T060112-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:cookiecuttr__2.0.3"
}
}
},
{
"category": "product_name",
"name": "Open Source Drupal REST \u0026 JSON API Authentication \u003c3.2.0",
"product": {
"name": "Open Source Drupal REST \u0026 JSON API Authentication \u003c3.2.0",
"product_id": "T060113",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:est__json_api_authentication__3.2.0"
}
}
},
{
"category": "product_name",
"name": "Open Source Drupal REST \u0026 JSON API Authentication 3.2.0",
"product": {
"name": "Open Source Drupal REST \u0026 JSON API Authentication 3.2.0",
"product_id": "T060113-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:est__json_api_authentication__3.2.0"
}
}
},
{
"category": "product_version_range",
"name": "Stop administrator login \u003c1.6",
"product": {
"name": "Open Source Drupal Stop administrator login \u003c1.6",
"product_id": "T060114"
}
},
{
"category": "product_version",
"name": "Stop administrator login 1.6",
"product": {
"name": "Open Source Drupal Stop administrator login 1.6",
"product_id": "T060114-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:stop_administrator_login__1.6"
}
}
},
{
"category": "product_version_range",
"name": "Tawk.to-Live chat application \u003c3.0.4",
"product": {
"name": "Open Source Drupal Tawk.to-Live chat application \u003c3.0.4",
"product_id": "T060115"
}
},
{
"category": "product_version",
"name": "Tawk.to-Live chat application 3.0.4",
"product": {
"name": "Open Source Drupal Tawk.to-Live chat application 3.0.4",
"product_id": "T060115-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:tawk.to_-_live_chat_application__3.0.4"
}
}
},
{
"category": "product_version_range",
"name": "Editoria11y Accessibility Checker \u003c2.2.23",
"product": {
"name": "Open Source Drupal Editoria11y Accessibility Checker \u003c2.2.23",
"product_id": "T060116"
}
},
{
"category": "product_version",
"name": "Editoria11y Accessibility Checker 2.2.23",
"product": {
"name": "Open Source Drupal Editoria11y Accessibility Checker 2.2.23",
"product_id": "T060116-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:editoria11y_accessibility_checker__2.2.23"
}
}
},
{
"category": "product_version_range",
"name": "Editoria11y Accessibility Checker \u003c3.0.9",
"product": {
"name": "Open Source Drupal Editoria11y Accessibility Checker \u003c3.0.9",
"product_id": "T060117"
}
},
{
"category": "product_version",
"name": "Editoria11y Accessibility Checker 3.0.9",
"product": {
"name": "Open Source Drupal Editoria11y Accessibility Checker 3.0.9",
"product_id": "T060117-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:editoria11y_accessibility_checker__3.0.9"
}
}
},
{
"category": "product_version_range",
"name": "Webform REST \u003c4.2.1",
"product": {
"name": "Open Source Drupal Webform REST \u003c4.2.1",
"product_id": "T060118"
}
},
{
"category": "product_version",
"name": "Webform REST 4.2.1",
"product": {
"name": "Open Source Drupal Webform REST 4.2.1",
"product_id": "T060118-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:webform_rest__4.2.1"
}
}
},
{
"category": "product_version_range",
"name": "AI CKEditor \u003c1.4.3",
"product": {
"name": "Open Source Drupal AI CKEditor \u003c1.4.3",
"product_id": "T060119"
}
},
{
"category": "product_version",
"name": "AI CKEditor 1.4.3",
"product": {
"name": "Open Source Drupal AI CKEditor 1.4.3",
"product_id": "T060119-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:ai_ckeditor__1.4.3"
}
}
},
{
"category": "product_version_range",
"name": "Combined image style \u003c1.0.7",
"product": {
"name": "Open Source Drupal Combined image style \u003c1.0.7",
"product_id": "T060120"
}
},
{
"category": "product_version",
"name": "Combined image style 1.0.7",
"product": {
"name": "Open Source Drupal Combined image style 1.0.7",
"product_id": "T060120-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:combined_image_style__1.0.7"
}
}
},
{
"category": "product_version_range",
"name": "CSS Usage Analyzer \u003c1.0.2",
"product": {
"name": "Open Source Drupal CSS Usage Analyzer \u003c1.0.2",
"product_id": "T060121"
}
},
{
"category": "product_version",
"name": "CSS Usage Analyzer 1.0.2",
"product": {
"name": "Open Source Drupal CSS Usage Analyzer 1.0.2",
"product_id": "T060121-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:css_usage_analyzer__1.0.2"
}
}
},
{
"category": "product_version_range",
"name": "Smart Content \u003c3.2.1",
"product": {
"name": "Open Source Drupal Smart Content \u003c3.2.1",
"product_id": "T060122"
}
},
{
"category": "product_version",
"name": "Smart Content 3.2.1",
"product": {
"name": "Open Source Drupal Smart Content 3.2.1",
"product_id": "T060122-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:smart_content__3.2.1"
}
}
},
{
"category": "product_version_range",
"name": "Diba carousel slider \u003c3.0.2",
"product": {
"name": "Open Source Drupal Diba carousel slider \u003c3.0.2",
"product_id": "T060123"
}
},
{
"category": "product_version",
"name": "Diba carousel slider 3.0.2",
"product": {
"name": "Open Source Drupal Diba carousel slider 3.0.2",
"product_id": "T060123-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:drupal:drupal:diba_carousel_slider__3.0.2"
}
}
}
],
"category": "product_name",
"name": "Drupal"
}
],
"category": "vendor",
"name": "Open Source"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-96355",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96355"
},
{
"cve": "CVE-2026-96356",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96356"
},
{
"cve": "CVE-2026-96357",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96357"
},
{
"cve": "CVE-2026-96358",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96358"
},
{
"cve": "CVE-2026-96359",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96359"
},
{
"cve": "CVE-2026-96360",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96360"
},
{
"cve": "CVE-2026-96361",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96361"
},
{
"cve": "CVE-2026-96362",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96362"
},
{
"cve": "CVE-2026-96363",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96363"
},
{
"cve": "CVE-2026-96364",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96364"
},
{
"cve": "CVE-2026-96365",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96365"
},
{
"cve": "CVE-2026-96366",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96366"
},
{
"cve": "CVE-2026-96367",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96367"
},
{
"cve": "CVE-2026-96368",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96368"
},
{
"cve": "CVE-2026-96369",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96369"
},
{
"cve": "CVE-2026-96370",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96370"
},
{
"cve": "CVE-2026-96371",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96371"
},
{
"cve": "CVE-2026-96372",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96372"
},
{
"cve": "CVE-2026-96373",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96373"
},
{
"cve": "CVE-2026-96374",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96374"
},
{
"cve": "CVE-2026-96375",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96375"
},
{
"cve": "CVE-2026-96376",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96376"
},
{
"cve": "CVE-2026-96377",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96377"
},
{
"cve": "CVE-2026-96378",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96378"
},
{
"cve": "CVE-2026-96379",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96379"
},
{
"cve": "CVE-2026-96380",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96380"
},
{
"cve": "CVE-2026-96382",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96382"
},
{
"cve": "CVE-2026-96384",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96384"
},
{
"cve": "CVE-2026-96385",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96385"
},
{
"cve": "CVE-2026-96386",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96386"
},
{
"cve": "CVE-2026-96387",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96387"
},
{
"cve": "CVE-2026-96388",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96388"
},
{
"cve": "CVE-2026-96390",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96390"
},
{
"cve": "CVE-2026-96391",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96391"
},
{
"cve": "CVE-2026-96392",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96392"
},
{
"cve": "CVE-2026-96398",
"product_status": {
"known_affected": [
"T060108",
"T060119",
"T060107",
"T060118",
"T060117",
"T060116",
"T060109",
"T060111",
"T060122",
"T060110",
"T060121",
"T060120",
"T060115",
"T060103",
"T060114",
"T060102",
"T060113",
"T060112",
"T060123"
]
},
"release_date": "2026-09-23T22:00:00.000+00:00",
"title": "CVE-2026-96398"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…