Drupal Next.js是Drupal社区的一个实现 Drupal 与 Next.js 深度集成的解耦模块。 Drupal Next.js 1.6.4之前版本和2.0.1之前版本存在安全漏洞,该漏洞源于跨域安全策略过于宽松,可能导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-14840 | HTTP Client Manager - Less critical - Information disclosure - SA-CONTRIB-2025-126 | |
| CVE-2025-14472 | Acquia Content Hub - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-12 | |
| CVE-2025-13986 | Disable Login Page - Critical - Access bypass - SA-CONTRIB-2025-124 | |
| CVE-2025-13985 | Entity Share - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-20 | |
| CVE-2025-13983 | Tagify - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-121 | |
| CVE-2025-13982 | Login Time Restriction - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-202 | |
| CVE-2025-13981 | AI (Artificial Intelligence) - Moderately critical - Cross-Site Scripting - SA-CONTRIB-202 | |
| CVE-2025-13980 | CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118 | |
| CVE-2025-13979 | Mini site - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-117 | |
| CVE-2026-0749 | Cross-Site Scripting Vulnerability in Drupal Form Builder Module | |
| CVE-2026-0750 | Payment bypass in Commerce Paybox |
No comments yet