Web Browser Cache Vulnerability in Drupal Core Affects Multiple Versions
CVE-2025-13083

3.7LOW

Key Information:

Vendor

Drupal

Vendor
CVE Published:
18 November 2025

What is CVE-2025-13083?

A vulnerability exists in Drupal core that enables exploitation through incorrectly configured access control security levels. This issue allows unauthorized access to sensitive information cached in web browsers, potentially exposing data to malicious users. Drupal versions impacted include releases from 8.0.0 up to 10.4.9, from 10.5.0 to 10.5.6, from 11.0.0 to 11.1.9, and from 11.2.0 to 11.2.8. Webmasters and administrators should ensure proper configuration of access security settings to mitigate risks associated with this vulnerability.

Affected Version(s)

Drupal core 8.0.0 < 10.4.9

Drupal core 10.5.0 < 10.5.6

Drupal core 11.0.0 < 11.1.9

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Damien McKenna (damienmckenna)
tame4tex
Benji Fisher (benjifisher)
catch (catch)
Neil Drumm (drumm)
Lee Rowlands (larowlan)
Mingsong (mingsong)
Mohit Aghera (mohit_aghera)
James Gilliland (neclimdul)
Juraj Nemec (poker10)
Jess (xjm)
catch (catch)
Lee Rowlands (larowlan)
Dave Long (longwave)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
.
CVE-2025-13083 : Web Browser Cache Vulnerability in Drupal Core Affects Multiple Versions