Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-13276 1 File Entity Project 1 File Entity 2025-09-02 7.5 High
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.
CVE-2024-13237 1 File Entity Project 1 File Entity 2025-06-04 5.4 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.38.