{"schema_version":1,"title":"Packagist:Https://Packages.drupal.org/8 Drupal/Social vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Packagist:Https://Packages.drupal.org/8 Drupal/Social: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-48921, was published on 25 June 2025.","url":"https://junglewise.ai/threats/technologies/drupal-social","json_url":"https://junglewise.ai/threats/technologies/drupal-social.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/drupal-social","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":16,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2025-48921","epss":0.0018,"slug":"cve-2025-48921-drupal-contrib-2025-079-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2025-079 - Open Social is a Drupal distribution for online communities, which ships with a default module that allows users to enroll in events. The m","severity":"info","exploited":false,"published_at":"2025-06-25T18:41:34+00:00","url":"https://junglewise.ai/threats/cve-2025-48921-drupal-contrib-2025-079-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2025-31686","cvss":3.1,"epss":0.004,"slug":"cve-2025-31686-drupal-contrib-2025-015-open-social-is-a-drupal-distribution-for","title":"Drupal Open Social Missing Authorization vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-31686-drupal-contrib-2025-015-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2025-31685","cvss":3.1,"epss":0.0038,"slug":"cve-2025-31685-drupal-contrib-2025-014-open-social-is-a-drupal-distribution-for","title":"Drupal Open Social Missing Authorization vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-31685-drupal-contrib-2025-014-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13274","cvss":3.1,"epss":0.0036,"slug":"cve-2024-13274-drupal-contrib-2024-038-open-social-is-a-drupal-distribution-for","title":"Drupal Open Social allows Functionality Misuse","severity":"low","exploited":false,"published_at":"2025-01-09T21:31:31+00:00","url":"https://junglewise.ai/threats/cve-2024-13274-drupal-contrib-2024-038-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13312","epss":0.003,"slug":"cve-2024-13312-drupal-contrib-2024-076-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2024-076 - Open Social is a Drupal distribution for online communities, which ships with a default (optional) module social\\_file\\_private to ensure th","severity":"info","exploited":false,"published_at":"2024-12-11T16:53:22+00:00","url":"https://junglewise.ai/threats/cve-2024-13312-drupal-contrib-2024-076-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13273","epss":0.0022,"slug":"cve-2024-13273-drupal-contrib-2024-037-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2024-037 - Open Social is a Drupal distribution for online communities, which ships with an optional module called Social Embed. This module allows a","severity":"info","exploited":false,"published_at":"2024-09-04T16:15:41+00:00","url":"https://junglewise.ai/threats/cve-2024-13273-drupal-contrib-2024-037-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13241","epss":0.0035,"slug":"cve-2024-13241-drupal-contrib-2024-005-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2024-005 - Open Social is a Drupal distribution for online communities. The included optional social\\_group\\_flexible\\_group module doesn't sufficient","severity":"info","exploited":false,"published_at":"2024-01-24T15:47:36+00:00","url":"https://junglewise.ai/threats/cve-2024-13241-drupal-contrib-2024-005-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13240","epss":0.0038,"slug":"cve-2024-13240-drupal-contrib-2024-004-content-within-open-social-can-have","title":"DRUPAL-CONTRIB-2024-004 - Content within Open Social can have different visibilities. It is possible for a user to create public content even when this should not be","severity":"info","exploited":false,"published_at":"2024-01-24T15:45:49+00:00","url":"https://junglewise.ai/threats/cve-2024-13240-drupal-contrib-2024-004-content-within-open-social-can-have"},{"slug":"drupal-contrib-2022-062-social-private-message-module-allows-users-on-d92d0105","title":"DRUPAL-CONTRIB-2022-062 - Social Private Message module allows users on the platform to allow users to send private messages to each other. The module does not prope","severity":"info","exploited":false,"published_at":"2022-11-30T15:34:03+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2022-062-social-private-message-module-allows-users-on-d92d0105"},{"slug":"drupal-contrib-2022-061-social-flexible-group-is-an-open-social-b7d0e2ee","title":"DRUPAL-CONTRIB-2022-061 - Social Flexible Group is an Open Social extension that allows users to create groups with many different configurations. In specific uncomm","severity":"info","exploited":false,"published_at":"2022-11-30T15:28:44+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2022-061-social-flexible-group-is-an-open-social-b7d0e2ee"},{"slug":"drupal-contrib-2022-043-open-social-is-a-drupal-distribution-for-online-f898aa34","title":"DRUPAL-CONTRIB-2022-043 - Open Social is a Drupal distribution for online communities. Group entities created within Open Social did not sufficiently check entity ac","severity":"info","exploited":false,"published_at":"2022-05-25T16:49:46+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2022-043-open-social-is-a-drupal-distribution-for-online-f898aa34"},{"slug":"drupal-contrib-2021-011-open-social-is-a-drupal-distribution-for-online-2a1a74ea","title":"DRUPAL-CONTRIB-2021-011 - Open Social is a Drupal distribution for online communities. The included social\\_magic\\_login module doesn't sufficiently validate magic l","severity":"info","exploited":false,"published_at":"2021-06-02T16:51:10+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2021-011-open-social-is-a-drupal-distribution-for-online-2a1a74ea"},{"slug":"drupal-contrib-2021-010-this-open-social-distribution-provides-a-turn-808e6c54","title":"DRUPAL-CONTRIB-2021-010 - This Open Social distribution provides a turn-key system for building customized social networks. The module doesn't sufficiently process d","severity":"info","exploited":false,"published_at":"2021-06-02T16:49:49+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2021-010-this-open-social-distribution-provides-a-turn-808e6c54"},{"slug":"drupal-contrib-2021-002-the-social-user-export-module-enables-users-d72b2b23","title":"DRUPAL-CONTRIB-2021-002 - The Social User Export module enables users within Open Social to create an export of users and download this to a CSV file. The module doe","severity":"info","exploited":false,"published_at":"2021-01-27T17:27:57+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2021-002-the-social-user-export-module-enables-users-d72b2b23"},{"slug":"drupal-contrib-2021-001-the-optional-social-auth-extra-module-enables-6cdc2493","title":"DRUPAL-CONTRIB-2021-001 - The optional Social Auth Extra module enables you to use the single sign-on methods provided by Open Social e.g. Facebook, LinkedIn, Google","severity":"info","exploited":false,"published_at":"2021-01-27T17:17:43+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2021-001-the-optional-social-auth-extra-module-enables-6cdc2493"},{"slug":"drupal-contrib-2019-075-open-social-is-a-drupal-distribution-for-online-c9160efd","title":"DRUPAL-CONTRIB-2019-075 - Open Social is a Drupal distribution for online communities. The included social\\_magic\\_login module doesn't sufficiently validate magic lo","severity":"info","exploited":false,"published_at":"2019-11-06T16:10:25+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2019-075-open-social-is-a-drupal-distribution-for-online-c9160efd"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Webform","slug":"drupal-webform","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/drupal-webform"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml","slug":"drupal-miniorange-saml","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-saml"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Ai","slug":"drupal-ai","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/drupal-ai"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Jsonapi","slug":"drupal-jsonapi","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-jsonapi"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange 2fa","slug":"drupal-miniorange-2fa","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-2fa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Facets","slug":"drupal-facets","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-facets"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Permissions By Term","slug":"drupal-permissions-by-term","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-permissions-by-term"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Tfa","slug":"drupal-tfa","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-tfa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Apigee Edge","slug":"drupal-apigee-edge","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-apigee-edge"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cleantalk","slug":"drupal-cleantalk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cleantalk"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Commerce","slug":"drupal-commerce","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-commerce"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cookies","slug":"drupal-cookies","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cookies"}],"technology":{"hub":true,"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Social","slug":"drupal-social","vendor":{"name":"Packagist:Https://Packages.drupal.org/8","slug":"packagist-https-packages-drupal-org-8","url":"https://junglewise.ai/threats/vendors/packagist-https-packages-drupal-org-8"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/drupal-social"},"most_severe":[{"cve":"CVE-2025-31686","cvss":3.1,"epss":0.004,"slug":"cve-2025-31686-drupal-contrib-2025-015-open-social-is-a-drupal-distribution-for","title":"Drupal Open Social Missing Authorization vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-31686-drupal-contrib-2025-015-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2025-31685","cvss":3.1,"epss":0.0038,"slug":"cve-2025-31685-drupal-contrib-2025-014-open-social-is-a-drupal-distribution-for","title":"Drupal Open Social Missing Authorization vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-31685-drupal-contrib-2025-014-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13274","cvss":3.1,"epss":0.0036,"slug":"cve-2024-13274-drupal-contrib-2024-038-open-social-is-a-drupal-distribution-for","title":"Drupal Open Social allows Functionality Misuse","severity":"low","exploited":false,"published_at":"2025-01-09T21:31:31+00:00","url":"https://junglewise.ai/threats/cve-2024-13274-drupal-contrib-2024-038-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13240","epss":0.0038,"slug":"cve-2024-13240-drupal-contrib-2024-004-content-within-open-social-can-have","title":"DRUPAL-CONTRIB-2024-004 - Content within Open Social can have different visibilities. It is possible for a user to create public content even when this should not be","severity":"info","exploited":false,"published_at":"2024-01-24T15:45:49+00:00","url":"https://junglewise.ai/threats/cve-2024-13240-drupal-contrib-2024-004-content-within-open-social-can-have"},{"cve":"CVE-2024-13241","epss":0.0035,"slug":"cve-2024-13241-drupal-contrib-2024-005-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2024-005 - Open Social is a Drupal distribution for online communities. The included optional social\\_group\\_flexible\\_group module doesn't sufficient","severity":"info","exploited":false,"published_at":"2024-01-24T15:47:36+00:00","url":"https://junglewise.ai/threats/cve-2024-13241-drupal-contrib-2024-005-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13312","epss":0.003,"slug":"cve-2024-13312-drupal-contrib-2024-076-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2024-076 - Open Social is a Drupal distribution for online communities, which ships with a default (optional) module social\\_file\\_private to ensure th","severity":"info","exploited":false,"published_at":"2024-12-11T16:53:22+00:00","url":"https://junglewise.ai/threats/cve-2024-13312-drupal-contrib-2024-076-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2024-13273","epss":0.0022,"slug":"cve-2024-13273-drupal-contrib-2024-037-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2024-037 - Open Social is a Drupal distribution for online communities, which ships with an optional module called Social Embed. This module allows a","severity":"info","exploited":false,"published_at":"2024-09-04T16:15:41+00:00","url":"https://junglewise.ai/threats/cve-2024-13273-drupal-contrib-2024-037-open-social-is-a-drupal-distribution-for"},{"cve":"CVE-2025-48921","epss":0.0018,"slug":"cve-2025-48921-drupal-contrib-2025-079-open-social-is-a-drupal-distribution-for","title":"DRUPAL-CONTRIB-2025-079 - Open Social is a Drupal distribution for online communities, which ships with a default module that allows users to enroll in events. The m","severity":"info","exploited":false,"published_at":"2025-06-25T18:41:34+00:00","url":"https://junglewise.ai/threats/cve-2025-48921-drupal-contrib-2025-079-open-social-is-a-drupal-distribution-for"},{"slug":"drupal-contrib-2022-062-social-private-message-module-allows-users-on-d92d0105","title":"DRUPAL-CONTRIB-2022-062 - Social Private Message module allows users on the platform to allow users to send private messages to each other. The module does not prope","severity":"info","exploited":false,"published_at":"2022-11-30T15:34:03+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2022-062-social-private-message-module-allows-users-on-d92d0105"},{"slug":"drupal-contrib-2022-061-social-flexible-group-is-an-open-social-b7d0e2ee","title":"DRUPAL-CONTRIB-2022-061 - Social Flexible Group is an Open Social extension that allows users to create groups with many different configurations. In specific uncomm","severity":"info","exploited":false,"published_at":"2022-11-30T15:28:44+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2022-061-social-flexible-group-is-an-open-social-b7d0e2ee"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}