CVE-2025-13083

CVE-2025-13083: Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008

Vendor Drupal
Product Drupal core
Weakness CWE-525
Published November 18, 2025
Last update January 16, 2026

CVSS base score

What the vulnerability does

Description

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.

Key dates

Disclosure timeline

November 18, 2025 CVE published
January 16, 2026 Record updated