{ "canonical_id": "drupal--47ee170dd0", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Moderately critical - Defacement - SA-CORE-2025-007", "summary": "
By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.
\nThe defacement is not stored and is only present when the URL has been crafted for that purpose. Only the defacement is present, so no other site content (such as branding) is rendered.
Install the latest version:
\nDrupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)