Known Vulnerabilities for Activity by Drupal
Listed below are 2 of the newest known vulnerabilities associated with "Activity" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65512 json | Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-64810 json | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tr... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-64112 json | In the Linux kernel, the following vulnerability has been resolved: rbd: eliminate a race in lock_dwork draining on unmap G... | Not Provided | 2026-07-19 | 2026-07-20 |
| CVE-2026-58460 json | react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application t... | Not Provided | 2026-07-02 | 2026-07-14 |
| CVE-2026-57848 json | Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via... | Not Provided | 2026-07-18 | 2026-07-20 |
| CVE-2026-56772 json | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notific... | Not Provided | 2026-06-25 | 2026-07-14 |
| CVE-2026-56694 json | NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleCha... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56005 json | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-55452 json | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent heade... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54806 json | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | Not Provided | 2026-06-17 | 2026-06-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Activity | 6.x-1.x |