Description
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Insertion of Sensitive Information Into Sent Data is a vulnerability that enables an attacker to forcefully retrieve data that should not be exposed. The weakness lies in how the DXPR Builder handles user requests, allowing an unauthorized user to craft requests that trigger the application to send back private or confidential information. This flaw is a classic information‑disclosure weakness and corresponds to CWE‑201.

Affected Systems

Drupal provides the DXPR Builder: The Best Editing (AI) Experience for Drupal, which is vulnerable in all releases from version 0.0.0 through 2.8.1 inclusive. Any installation of the component in this version range is susceptible to exploitation.

Risk and Exploitability

The exploit is likely to be performed via a forceful browsing attack, where an attacker submits crafted input to the component to read back protected data. The CVSS score is 5.3, indicating a moderate severity level, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, so no public exploitation data is presently reported. However, because the flaw permits disclosure of sensitive information without authentication, the impact on confidentiality is still high. Authorities should treat this as a moderate‑to‑critical risk until an official fix is deployed.

Generated by OpenCVE AI on September 3, 2026 at 10:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DXPR Builder to the latest release that is beyond version 2.8.1, as the vulnerability is known to affect all older versions.
  • Enforce strict role‑based access controls to limit who can send requests to the editor component, reducing the opportunity for a forced browsing attempt.
  • Regularly review Drupal security advisories and apply any forthcoming patches or updates as soon as they are available.

Generated by OpenCVE AI on September 3, 2026 at 10:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Dxpr Builder Project
Dxpr Builder Project dxpr Builder
CPEs cpe:2.3:a:dxpr_builder_project:dxpr_builder:*:*:*:*:*:drupal:*:*
Vendors & Products Dxpr Builder Project
Dxpr Builder Project dxpr Builder

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal dxpr Builder: The Best Editing (ai) Experience For Drupal
Vendors & Products Drupal
Drupal dxpr Builder: The Best Editing (ai) Experience For Drupal

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
Title DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
Weaknesses CWE-201
References

Subscriptions

Drupal Dxpr Builder: The Best Editing (ai) Experience For Drupal
Dxpr Builder Project Dxpr Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T19:07:20.935Z

Reserved: 2026-08-26T16:19:44.579Z

Link: CVE-2026-81162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:12.023

Modified: 2026-09-09T18:51:17.167

Link: CVE-2026-81162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:00:03Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data