{"schema_version":1,"title":"Packagist:Https://Packages.drupal.org/8 Drupal/Tfa vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in Packagist:Https://Packages.drupal.org/8 Drupal/Tfa: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-7030, was published on 2 July 2025.","url":"https://junglewise.ai/threats/technologies/drupal-tfa","json_url":"https://junglewise.ai/threats/technologies/drupal-tfa.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/drupal-tfa","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":5,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2025-7030","epss":0.0036,"slug":"cve-2025-7030-drupal-contrib-2025-085-this-module-enables-you-to-allow-and-or","title":"DRUPAL-CONTRIB-2025-085 - This module enables you to allow and/or require a second authentication method in addition to password authentication. The module does not","severity":"info","exploited":false,"published_at":"2025-07-02T17:37:03+00:00","url":"https://junglewise.ai/threats/cve-2025-7030-drupal-contrib-2025-085-this-module-enables-you-to-allow-and-or"},{"cve":"CVE-2025-31694","cvss":3.1,"epss":0.0039,"slug":"cve-2025-31694-drupal-contrib-2025-023-this-module-enables-you-to-allow-and-or","title":"Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:35+00:00","url":"https://junglewise.ai/threats/cve-2025-31694-drupal-contrib-2025-023-this-module-enables-you-to-allow-and-or"},{"cve":"CVE-2024-13279","epss":0.0046,"slug":"cve-2024-13279-drupal-contrib-2024-043-this-module-enables-you-to-allow-and-or","title":"DRUPAL-CONTRIB-2024-043 - This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. The mod","severity":"info","exploited":false,"published_at":"2024-10-02T16:20:48+00:00","url":"https://junglewise.ai/threats/cve-2024-13279-drupal-contrib-2024-043-this-module-enables-you-to-allow-and-or"},{"cve":"CVE-2024-13239","epss":0.0056,"slug":"cve-2024-13239-drupal-contrib-2024-003-this-module-enables-you-to-allow-and-or","title":"DRUPAL-CONTRIB-2024-003 - This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. In some","severity":"info","exploited":false,"published_at":"2024-01-24T15:42:46+00:00","url":"https://junglewise.ai/threats/cve-2024-13239-drupal-contrib-2024-003-this-module-enables-you-to-allow-and-or"},{"slug":"drupal-contrib-2023-030-this-module-enables-you-to-allow-and-or-require-f813a9d4","title":"DRUPAL-CONTRIB-2023-030 - This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. The mod","severity":"info","exploited":false,"published_at":"2023-07-12T18:19:42+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2023-030-this-module-enables-you-to-allow-and-or-require-f813a9d4"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Webform","slug":"drupal-webform","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/drupal-webform"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Social","slug":"drupal-social","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/drupal-social"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml","slug":"drupal-miniorange-saml","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-saml"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Ai","slug":"drupal-ai","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/drupal-ai"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Jsonapi","slug":"drupal-jsonapi","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-jsonapi"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange 2fa","slug":"drupal-miniorange-2fa","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-2fa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Facets","slug":"drupal-facets","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-facets"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Permissions By Term","slug":"drupal-permissions-by-term","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-permissions-by-term"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Apigee Edge","slug":"drupal-apigee-edge","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-apigee-edge"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cleantalk","slug":"drupal-cleantalk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cleantalk"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Commerce","slug":"drupal-commerce","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-commerce"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cookies","slug":"drupal-cookies","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cookies"}],"technology":{"hub":true,"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Tfa","slug":"drupal-tfa","vendor":{"name":"Packagist:Https://Packages.drupal.org/8","slug":"packagist-https-packages-drupal-org-8","url":"https://junglewise.ai/threats/vendors/packagist-https-packages-drupal-org-8"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/drupal-tfa"},"most_severe":[{"cve":"CVE-2025-31694","cvss":3.1,"epss":0.0039,"slug":"cve-2025-31694-drupal-contrib-2025-023-this-module-enables-you-to-allow-and-or","title":"Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:35+00:00","url":"https://junglewise.ai/threats/cve-2025-31694-drupal-contrib-2025-023-this-module-enables-you-to-allow-and-or"},{"cve":"CVE-2024-13239","epss":0.0056,"slug":"cve-2024-13239-drupal-contrib-2024-003-this-module-enables-you-to-allow-and-or","title":"DRUPAL-CONTRIB-2024-003 - This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. In some","severity":"info","exploited":false,"published_at":"2024-01-24T15:42:46+00:00","url":"https://junglewise.ai/threats/cve-2024-13239-drupal-contrib-2024-003-this-module-enables-you-to-allow-and-or"},{"cve":"CVE-2024-13279","epss":0.0046,"slug":"cve-2024-13279-drupal-contrib-2024-043-this-module-enables-you-to-allow-and-or","title":"DRUPAL-CONTRIB-2024-043 - This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. The mod","severity":"info","exploited":false,"published_at":"2024-10-02T16:20:48+00:00","url":"https://junglewise.ai/threats/cve-2024-13279-drupal-contrib-2024-043-this-module-enables-you-to-allow-and-or"},{"cve":"CVE-2025-7030","epss":0.0036,"slug":"cve-2025-7030-drupal-contrib-2025-085-this-module-enables-you-to-allow-and-or","title":"DRUPAL-CONTRIB-2025-085 - This module enables you to allow and/or require a second authentication method in addition to password authentication. The module does not","severity":"info","exploited":false,"published_at":"2025-07-02T17:37:03+00:00","url":"https://junglewise.ai/threats/cve-2025-7030-drupal-contrib-2025-085-this-module-enables-you-to-allow-and-or"},{"slug":"drupal-contrib-2023-030-this-module-enables-you-to-allow-and-or-require-f813a9d4","title":"DRUPAL-CONTRIB-2023-030 - This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. The mod","severity":"info","exploited":false,"published_at":"2023-07-12T18:19:42+00:00","url":"https://junglewise.ai/threats/drupal-contrib-2023-030-this-module-enables-you-to-allow-and-or-require-f813a9d4"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}