Drupal Plausible tracking是Drupal社区的一款数据分析插件。 Drupal Plausible tracking 1.0.2之前版本存在安全漏洞,该漏洞源于网页生成期间输入中和不当,可能导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Plausible tracking | 0.0.0 ~ 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12466 | Simple OAuth (OAuth2) & OpenID Connect - Critical - Access bypass - SA-CONTRIB-2025-114 | |
| CVE-2025-12083 | CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-11 | |
| CVE-2025-12082 | CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025- | |
| CVE-2025-10929 | Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111 | |
| CVE-2025-10930 | Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110 | |
| CVE-2025-10931 | Umami Analytics - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-109 | |
| CVE-2025-10928 | Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108 | |
| CVE-2025-10926 | JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106 | |
| CVE-2025-9954 | Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025 |
No comments yet