Drupal core – Moderately critical – Defacement – SA-CORE-2025-007

SecurityVulns

Project: Drupal coreDate: 2025-November-12Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:AllVulnerability: DefacementAffected versions: >= 8.0.0 < 10.4.9 || >= 10.5.0 < 10.5.6 || >= 11.0.0 < 11.1.9 || >= 11.2.0 < 11.2.8CVE IDs: CVE-2025-13082Description: By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.
The defacement is not stored and is only present when the URL has been crafted for that purpose. Only the defacement is present, so no other site content (such as branding) is rendered.Solution: Install the latest version:

If you are using Drupal 10.4, update to Drupal 10.4.9.
If you are using Drupal 10.5, update to Drupal 10.5.6.
If you are using Drupal 11.1, update to Drupal 11.1.9.
If you are using Drupal 11.2, update to Drupal 11.2.8.

Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)Reported By: 
Kevin Quillen (kevinquillen)
Fixed By: 
Benji Fisher (benjifisher) of the Drupal Security Team
Neil Drumm (drumm) of the Drupal Security Team
Greg Knaddison (greggles) of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Mingsong (mingsong), provisional member of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security Team
Ra Mänd (ram4nd), provisional member of the Drupal Security Team
Jess (xjm) of the Drupal Security Team
Coordinated By: 
catch (catch) of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security TeamSecurity advisoriesRead More