Drupal Umami Analytics是Drupal社区的一款网页数据统计插件。 Drupal Umami Analytics 1.0.1之前版本存在安全漏洞,该漏洞源于网页生成期间输入中和不当,可能导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Umami Analytics | 0.0.0 ~ 1.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12466 | Simple OAuth (OAuth2) & OpenID Connect - Critical - Access bypass - SA-CONTRIB-2025-114 | |
| CVE-2025-12083 | CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-11 | |
| CVE-2025-12082 | CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025- | |
| CVE-2025-10929 | Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111 | |
| CVE-2025-10930 | Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110 | |
| CVE-2025-10928 | Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108 | |
| CVE-2025-10927 | Plausible tracking - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-107 | |
| CVE-2025-10926 | JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106 | |
| CVE-2025-9954 | Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025 |
No comments yet