Known Vulnerabilities for Entity API by Drupal
Listed below are 10 of the newest known vulnerabilities associated with "Entity API" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-83610 json | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xm... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-82958 json | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateT... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82880 json | YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch par... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-82745 json | Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mn... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-82633 json | Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpo... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-81164 json | Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: fr... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-81158 json | Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: ... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-80650 json | In the Linux kernel, the following vulnerability has been resolved: media: atomisp: gc2235: fix UAF and memory leak gc2235_... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-78681 json | NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in d... | Not Provided | 2026-08-25 | 2026-08-26 |
| CVE-2026-78601 json | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorizatio... | Not Provided | 2026-09-02 | 2026-09-02 |