Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4442 articles · 179515 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-13240PATCHED
drupal · paragraphs

Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060

Description

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

Affected Products

VendorProductVersions
drupalparagraphs0.0.0

References

  • https://www.drupal.org/sa-contrib-2026-060

Related News (2 articles)

Tier C
VulDB11d ago
CVE-2026-13240 | Drupal Paragraphs up to 1.20.x Authorization authorization
→ No new info (linked only)
Tier B
BSI Advisories27d ago
[NEU] [mittel] Drupal: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.21.0
CWECWE-862
PublishedJul 10, 2026
Last enriched11d agov2
Trending Score11
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Drupal Internationalization Single Sign-On Access Bypass
Trending: 30
CRITICALCVE-2026-11913
Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
Trending: 15
MEDIUMCVE-2026-13242
Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
Trending: 12
CRITICALCVE-2026-12535EXP
Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
Trending: 11
HIGHCVE-2026-15081EXP
Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: affectedVersions, severity
Jul 11, 2026
Patch Available
Jul 13, 2026

Version History

v2
Last enriched 11d ago
v2Tier C11d ago

Updated affected versions to include 1.20.0, changed severity to HIGH, and corrected exploit availability status.

affectedVersionsseverity
via VulDB
v112d ago

Initial creation