Known Vulnerabilities for Link by Drupal
Listed below are 10 of the newest known vulnerabilities associated with "Link" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68582 json | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collecti... | Not Provided | 2026-08-02 | 2026-08-02 |
| CVE-2026-68581 json | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-... | Not Provided | 2026-08-02 | 2026-08-02 |
| CVE-2026-67530 json | WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/autom... | Not Provided | 2026-07-30 | 2026-07-31 |
| CVE-2026-67335 json | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backe... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-67327 json | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to a... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-66825 json | Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-li... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-66395 json | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-65912 json | DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via E... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65710 json | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLIC... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-65606 json | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins... | Not Provided | 2026-07-23 | 2026-07-23 |