CVE-2025-13082

CVE-2025-13082: Drupal core - Moderately critical - Defacement - SA-CORE-2025-007

Vendor Drupal
Product Drupal core
Weakness CWE-451
Published November 18, 2025
Last update November 18, 2025

CVSS base score

What the vulnerability does

Description

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

Key dates

Disclosure timeline

November 18, 2025 CVE published
November 18, 2025 Record updated