{ "canonical_id": "drupal--47ee170dd0", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Moderately critical - Defacement - SA-CORE-2025-007", "summary": "
Project: 
Date: 
2025-November-12
Security risk: 
Vulnerability: 
Defacement
Affected versions: 
>= 8.0.0 < 10.4.9 || >= 10.5.0 < 10.5.6 || >= 11.0.0 < 11.1.9 || >= 11.2.0 < 11.2.8
CVE IDs: 
CVE-2025-13082
Description: 

By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.

\n

The defacement is not stored and is only present when the URL has been crafted for that purpose. Only the defacement is present, so no other site content (such as branding) is rendered.

Solution: 

Install the latest version:

\n\n

Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)

Reported By: 
Fixed By: 
Coordinated By: 
", "published_at": "Wed, 12 Nov 2025 20:16:21 +0000", "updated_at": "Wed, 12 Nov 2025 20:16:21 +0000", "severity": "unknown", "cvss_score": null, "exploit_status": "unknown", "source_confidence": "official", "official_source_url": "https://www.drupal.org/sa-core-2025-007", "secondary_source_urls": [], "aliases": [], "cve_ids": [], "ghsa_ids": [], "osv_ids": [], "affected_versions": [], "fixed_versions": [], "package_name": null, "render_markdown": false, "case_path": null, "secure_code_topics": [ "authz-server-side-recheck", "xss-output-encoding", "file-upload-validation", "plugin-extension-trust-policy" ], "status": "triage", "triage_reasons": [ "missing affected/fixed version details" ], "verification_status": "triage-manual", "verification_mode": "synthetic", "last_verified_at": null, "last_run_id": null, "evidence_bundle": null, "historical_status": null, "latest_status": null, "browser_evidence": { "required": false, "present": false, "refs": [] }, "repro_profile_id": "xss-generic", "artifact_mode": "official-image", "blocked_reason": null, "metadata": { "source_names": [ "Drupal Security Advisories RSS" ], "source_kinds": [ "rss-feed" ], "candidate_count": 1 } }