Known Vulnerabilities for Data by Drupal
Listed below are 2 of the newest known vulnerabilities associated with "Data" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49491 json | Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by inje... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-49489 json | OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that... | Not Provided | 2026-05-31 | 2026-06-01 |
| CVE-2026-49377 json | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-49130 json | Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function withi... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-49002 json | Access control failure means that an application does not effectively check user access permissions, so that unauthorized use... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-49001 json | Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-si... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-49000 json | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate ke... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-48999 json | Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-48920 json | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting ... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-48919 json | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | Not Provided | 2026-05-27 | 2026-05-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Data | 6.x-1.0 |