SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81162

MEDIUM · CVSS 5.3 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The DXPR Builder for Drupal, specifically versions 0.0.0 to 2.8.1, is vulnerable to forceful browsing, which can lead to the unintentional exposure of sensitive information in sent data. This vulnerability may allow unauthorized users to access restricted content, potentially compromising user privacy and data integrity. Organizations using this component should prioritize patching or upgrading to mitigate the risk of data leakage.

CVE
CVE-2026-81162
Severity
MEDIUM
CVSS
5.3
EPSS
0.33%

Original NVD Description

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.