Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

core — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories and vulnerability records for the product core. It collects entries spanning multiple years, covering various weakness classes including buffer overflows, memory corruption, and access control flaws. Readers can track the vendor's published advisories, understand the evolution of specific weakness categories, and review the product's complete vulnerability history to identify recurring patterns. The dataset includes both confirmed and unpatched issues, enabling users to assess the overall risk profile and remediation status over time. By correlating vulnerability reports with patch releases, the page helps teams prioritize updates and verify that known defects have been addressed in the latest build.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2026-27621 TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload CWE-79 5.4AI Medium AI 2026-02-25
CVE-2026-25577 Emmett has an Unhandled CookieError Exception Causing Denial of Service CWE-248 7.5 High 2026-02-10
CVE-2026-25762 AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection CWE-400 7.5 High 2026-02-06
CVE-2026-25754 AdonisJS multipart body parsing has Prototype Pollution issue CWE-1321 7.2 High 2026-02-06
CVE-2026-21440 AdonisJS Path Traversal in Multipart File Handling CWE-22 7.5 - 2026-01-02
CVE-2025-62370 Alloy Core has a DoS vulnerability on `alloy_dyn_abi::TypedData` hashing CWE-248 7.5 High 2025-10-15
CVE-2025-59429 FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status page CWE-79 6.1AI Medium AI 2025-10-14
CVE-2025-62172 Home Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Name CWE-80 5.4AI Medium AI 2025-10-14
CVE-2014-125127 Denial of Service (DoS) vulnerability in mikecao/flight CWE-770 7.5 High 2025-09-03
CVE-2025-31485 GraphQL grant on a property might be cached with different objects CWE-696 7.5 High 2025-04-03
CVE-2025-31481 GraphQL query operations security can be bypassed CWE-863 7.5 High 2025-04-03
CVE-2023-47639 API Platform Core can leak exceptions message that may contain sensitive information CWE-209 5.3 Medium 2025-04-03
CVE-2025-23204 GraphQl securityAfterResolver not called CWE-20 4.4 Medium 2025-03-24
CVE-2025-25305 SSL validation for outgoing requests in Home Assistant Core and used libs not correct CWE-940 7.0 High 2025-02-18
CVE-2023-50715 User accounts disclosed to unauthenticated actors on the LAN CWE-200 4.3 Medium 2023-12-15
CVE-2023-41893 Account takeover via auth_callback login in Home Assistant Core CWE-200 4.3 Medium 2023-10-19
CVE-2023-41894 Local-only webhooks externally accessible via SniTun in Home Assistant Core CWE-669 5.3 Medium 2023-10-19
CVE-2023-41895 Cross-site Scripting via auth_callback login in Home Assistant Core CWE-79 8.8 High 2023-10-19
CVE-2023-41896 Fake websocket server installation permits full takeover in Home Assistant Core CWE-345 7.1 High 2023-10-19
CVE-2023-41897 Lack of XFO header allows clickjacking in Home Assistant Core CWE-1021 8.8 High 2023-10-19
CVE-2023-41899 Partial Server-Side Request Forgery in Home Assistant Core CWE-918 6.6 Medium 2023-10-19
CVE-2023-41898 Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for Android CWE-345 8.6 High 2023-10-19
CVE-2023-44385 Client-Side Request Forgery in Home Assistant iOS/macOS native Apps CWE-352 8.6 High 2023-10-19
CVE-2023-5256 Drupal core - Critical - Cache poisoning - SA-CORE-2023-006 CWE-200 9.1 - 2023-09-28
CVE-2023-31250 Drupal core - Moderately critical - Access bypass - SA-CORE-2023-005 6.5 - 2023-04-26
CVE-2022-25278 Drupal 访问控制错误漏洞 6.5 - 2023-04-26
CVE-2022-25277 Drupal 代码问题漏洞 8.2 - 2023-04-26
CVE-2022-25276 Drupal 跨站脚本漏洞 6.1 - 2023-04-26
CVE-2022-25275 Drupal 安全漏洞 8.8 - 2023-04-26
CVE-2022-25274 Drupal 安全漏洞 8.1 - 2023-04-26

All 137 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.