CVE-2026-81162

Source
https://cve.org/CVERecord?id=CVE-2026-81162
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81162.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81162
Aliases
Published
2026-09-02T12:31:58Z
Modified
2026-09-11T03:30:32Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
Details

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

Database specific
{
    "cna_assigner": "drupal",
    "cwe_ids": [
        "CWE-201"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81162.json"
}
References

Affected packages

Git / git.drupalcode.org/project/dxpr_builder

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/dxpr_builder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
5696af977955434fefa5cc25517806996092bcd1
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.0.0"
        },
        {
            "fixed": "2.8.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.0
2.0.0-RC1
2.0.0-rc1
2.0.0-rc2
2.0.0-rc3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0-alpha3
2.2.0-alpha4
2.2.0-beta1
2.2.0-beta2
2.2.0-rc1
2.2.1
2.2.2
2.2.2-beta1
2.2.2-beta2
2.2.3
2.2.3-alpha1
2.2.3-alpha2
2.2.3-alpha3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.3.0
2.3.1
2.3.2-beta1
2.4.0
2.5.0
2.5.3
2.5.4
2.5.5-alpha1
2.6.0
2.6.1-alpha1
2.6.1-beta1
2.6.1-beta2
2.6.1-beta3
2.6.1-beta5
2.7.0
2.7.0-beta10
2.7.0-beta11
2.7.0-beta13
2.7.0-beta8
2.7.1
2.7.3
2.7.4
2.7.5
2.7.6-alpha1
2.8.0
2.8.0-alpha10
2.8.0-alpha11
2.8.0-alpha12
2.8.0-alpha13
2.8.0-alpha14
2.8.0-alpha15
2.8.0-alpha16
2.8.0-alpha17
2.8.0-alpha18
2.8.0-alpha19
2.8.0-alpha2
2.8.0-alpha20
2.8.0-alpha21
2.8.0-alpha23
2.8.0-alpha24
2.8.0-alpha25
2.8.0-alpha27
2.8.0-alpha3
2.8.0-alpha4
2.8.0-alpha5
2.8.0-alpha7
2.8.0-alpha8
2.8.0-alpha9
2.8.0-beta1
2.8.0-beta2
2.8.0-beta3
2.8.0-rc1
2.8.0-rc2
2.8.0-rc3
2.8.1-beta1
3.*
3.0.0-alpha2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81162.json"