Known vulnerabilities in Enterprise MFA - TFA for Drupal
Vendor:
gauravsood91
Software:
Enterprise MFA - TFA for Drupal
Software CPE:
cpe:2.3:a:gauravsood91:enterprise_mfa_-_tfa_for_drupal:*:*:*:*:*:*:*:*
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU111956 - Improper Authorization CVE-2025-6675 |
CWE-285 | Medium | 4.8.0, 5.2.1 | 26.06.2025 |
SB2025062612 |
||
| #VU108908 - Improper Access Control CVE-2025-47710 |
CWE-284 | Medium | 4.7.0, 5.2.0 | 12.05.2025 |
SB2025051205 |
||
| #VU108906 - Improper Access Control CVE-2025-47709 |
CWE-284 | Medium | 4.7.0, 5.2.0 | 12.05.2025 |
SB2025051205 |
||
| #VU108905 - Improper Access Control CVE-2025-47707 |
CWE-284 | Low | 4.7.0, 5.2.0 | 12.05.2025 |
SB2025051205 |
||
| #VU108904 - Improper Access Control CVE-2025-47706 |
CWE-284 | Medium | 4.7.0, 5.2.0 | 12.05.2025 |
SB2025051205 |
||
| #VU108903 - Cross-Site Request Forgery (CSRF) CVE-2025-47708 |
CWE-352 | Low | 4.7.0, 5.2.0 | 12.05.2025 |
SB2025051205 |