Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4437 articles · 179523 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-12535EXPLOITEDPATCHED
drupal · formatter field

Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

Affected Products

VendorProductVersions
drupalformatter field0.0.0

References

  • https://www.drupal.org/sa-contrib-2026-048

Related News (2 articles)

Tier C
VulDB12d ago
CVE-2026-12535 | Drupal Formatter Field up to 1.x injection
→ No new info (linked only)
Tier B
BSI Advisories34d ago
[NEU] [hoch] Drupal Module: Mehrere Schwachstellen ermöglichen Manipulation von Daten
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.0.0
CWECWE-915
PublishedJul 10, 2026
Last enriched11d agov2
Trending Score11
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Drupal Internationalization Single Sign-On Access Bypass
Trending: 30
CRITICALCVE-2026-11913
Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
Trending: 15
MEDIUMCVE-2026-13242
Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
Trending: 12
MEDIUMCVE-2026-13240
Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
Trending: 11
HIGHCVE-2026-15081EXP
Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: description, severity, affectedVersions, activelyExploited
Jul 10, 2026
Actively Exploited
Jul 13, 2026
Patch Available
Jul 13, 2026

Version History

v2
Last enriched 11d ago
v2Tier C11d ago

Updated severity to CRITICAL, added affected versions 1.x, and corrected exploit availability to false.

descriptionseverityaffectedVersionsactivelyExploited
via VulDB
v112d ago

Initial creation