Known Vulnerabilities for Activity by Drupal
Listed below are 2 of the newest known vulnerabilities associated with "Activity" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-24987 | Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Acc... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-5199 | A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim na... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2025-62760 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Act... | Not Provided | 2025-12-31 | 2026-04-01 |
| CVE-2025-47548 | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity... | Not Provided | 2025-05-07 | 2026-04-01 |
| CVE-2025-31006 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Activity React... | Not Provided | 2025-04-17 | 2026-04-01 |
| CVE-2025-30957 | Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Exploi... | Not Provided | 2025-06-06 | 2026-04-01 |
| CVE-2025-24718 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activity-log.com WP Ses... | Not Provided | 2025-01-31 | 2026-04-01 |
| CVE-2024-51814 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 野人 活动链接推�... | Not Provided | 2024-11-19 | 2026-04-01 |
| CVE-2024-49681 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Ses... | Not Provided | 2024-10-24 | 2026-04-01 |
| CVE-2012-2079 | A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. | 8.8 - HIGH | 2019-11-22 | 2019-12-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Activity | 6.x-1.x | All | All | All |