Known Vulnerabilities for Data by Drupal
Listed below are 2 of the newest known vulnerabilities associated with "Data" by "Drupal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56446 json | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Bec... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56424 json | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, ... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56422 json | Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) an... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56385 json | Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56357 json | n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to imple... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56355 json | GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization. | Not Provided | 2026-06-20 | 2026-06-22 |
| CVE-2026-56348 json | n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56341 json | AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorizatio... | Not Provided | 2026-06-20 | 2026-06-22 |
| CVE-2026-56321 json | Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /priva... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-56317 json | Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component ... | Not Provided | 2026-06-20 | 2026-06-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Data | 6.x-1.0 |