CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-18261 MEDIUM

CVE-2026-18261 published: Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

View full advisory →
CVE-2026-15916 MEDIUM

CVE-2026-15916 published: Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

View full advisory →
CVE-2026-15917 MEDIUM

CVE-2026-15917 published: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to...

View full advisory →
CVE-2026-16638 MEDIUM

CVE-2026-16638 published: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.

View full advisory →
CVE-2026-16639 CRITICAL

CVE-2026-16639 published: Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

View full advisory →
CVE-2026-16640 MEDIUM

CVE-2026-16640 published: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.

View full advisory →
CVE-2026-16641 CRITICAL

CVE-2026-16641 published: Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

View full advisory →
CVE-2026-16642 MEDIUM

CVE-2026-16642 published: Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

View full advisory →
CVE-2026-15088 MEDIUM

CVE-2026-15088 published: Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.

View full advisory →
CVE-2026-38474 UNKNOWN

CVE-2026-38474 published: GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts...

View full advisory →
CVE-2026-62861 UNKNOWN

CVE-2026-62861 published: TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.t...

View full advisory →
CVE-2026-62862 UNKNOWN

CVE-2026-62862 published: Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email provider overrides Ne...

View full advisory →
CVE-2026-62865 UNKNOWN

CVE-2026-62865 published: Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebot variable, and its ...

View full advisory →
CVE-2026-63403 UNKNOWN

CVE-2026-63403 published: Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and several ...

View full advisory →
CVE-2026-63404 UNKNOWN

CVE-2026-63404 published: Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It w...

View full advisory →
CVE-2026-38465 UNKNOWN

CVE-2026-38465 published: A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the avatar_mouse_over_text parameter...

View full advisory →
CVE-2026-38466 UNKNOWN

CVE-2026-38466 published: A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the remaster_custom_title parameter...

View full advisory →
CVE-2026-38467 UNKNOWN

CVE-2026-38467 published: A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands via the tagid or type parameter ...

View full advisory →
CVE-2026-38468 UNKNOWN

CVE-2026-38468 published: A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_view_ips privileges to execute arbitrary SQL commands via the ip ...

View full advisory →
CVE-2026-38469 UNKNOWN

CVE-2026-38469 published: A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the title parameter in /bonus.php and /user.ph...

View full advisory →