Drupal Internationalization Single Sign-On 模块中存在“通过备用路径或通道绕过身份验证”漏洞,该漏洞可导致身份验证被绕过。此问题影响 Internationalization Single Sign-On 模块的所有版本,从 0.0.0 到 1.8.0。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Internationalization Single Sign-On | 0.0.0 ~ 1.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15088 | Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089 | |
| CVE-2026-15917 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011 | |
| CVE-2026-15916 | Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010 | |
| CVE-2026-16641 | Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084 | |
| CVE-2026-16643 | Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086 | |
| CVE-2026-16640 | Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082 | |
| CVE-2026-16646 | PanKM - Critical - Unsupported - SA-CONTRIB-2026-083 | |
| CVE-2026-16645 | PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypa | |
| CVE-2026-16644 | Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087 | |
| CVE-2026-16638 | Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080 | |
| CVE-2026-16642 | Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085 | |
| CVE-2026-18261 | Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092 | |
| CVE-2026-18985 | Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093 | |
| CVE-2026-18260 | Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091 | |
| CVE-2026-18259 | Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090 | |
| CVE-2026-55805 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012 |
No comments yet