CVE-2025-13082: Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
Other sources
User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13082?
The severity of CVE-2025-13082 is considered to be high due to its potential for content spoofing.
How do I fix CVE-2025-13082?
To fix CVE-2025-13082, upgrade Drupal core to versions 10.5.6 or 11.2.8 or later.
Which versions of Drupal are affected by CVE-2025-13082?
CVE-2025-13082 affects Drupal core versions from 8.0.0 before 10.4.9, and from 10.5.0 before 10.5.6, as well as from 11.0.0 before 11.1.9 and from 11.2.0 before 11.2.8.
What type of vulnerability is CVE-2025-13082?
CVE-2025-13082 is a User Interface (UI) Misrepresentation vulnerability that allows for content spoofing.
Is there a workaround for CVE-2025-13082?
There is no specific workaround for CVE-2025-13082; upgrading to the latest version is the recommended resolution.