5.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
Basic Information
ID
CVE-2025-13081
Source
drupal
Published
Nov 18, 2025 at 16:54
Modified
Nov 18, 2025 at 17:26
Affected Product
Vendor
Drupal
Product
Drupal core
Version
8.0.0
Affected Versions
Drupal Drupal core 8.0.0
Drupal Drupal core 10.5.0
Drupal Drupal core 11.0.0
Drupal Drupal core 11.2.0
Drupal Drupal core 10.5.0
Drupal Drupal core 11.0.0
Drupal Drupal core 11.2.0