CVE-2025-13082

MEDIUM4.3EPSS 0.04%

Drupal core - Moderately critical - Defacement - SA-CORE-2025-007

Published: 11/12/2025Modified: 12/10/2025
Also known as:GHSA-h89p-5896-f4q8BIT-drupal-2025-13082DRUPAL-CORE-2025-007

Description

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

References (3)