Drupal 内容审核通知(Content Moderation Notifications)模块中存在“权限定义包含不安全操作”的漏洞,该漏洞可导致权限提升(Privilege Escalation)。受影响版本为 0.0.0 至 3.9.0。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Content Moderation Notifications | 0.0.0 ~ 3.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76759 | Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 | |
| CVE-2026-81160 | Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117 | |
| CVE-2026-81201 | Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116 | |
| CVE-2026-81205 | LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CO | |
| CVE-2026-81164 | Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114 | |
| CVE-2026-81158 | Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113 | |
| CVE-2026-81162 | DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information D | |
| CVE-2026-81166 | Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109 | |
| CVE-2026-81269 | Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108 | |
| CVE-2026-81159 | Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-20 | |
| CVE-2026-81168 | CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105 | |
| CVE-2026-81165 | Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104 | |
| CVE-2026-81167 | Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103 | |
| CVE-2026-16647 | Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 | |
| CVE-2026-76782 | Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102 | |
| CVE-2026-76758 | Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101 | |
| CVE-2026-76755 | Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 | |
| CVE-2026-76756 | Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 | |
| CVE-2026-76757 | Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 | |
| CVE-2026-73477 | Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet