CVE-2025-14472: Acquia Content Hub - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-125
Published Jan 28, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub: from 0.0.0 before 3.6.4, from 3.7.0 before 3.7.3.
Affected Software
3 affected components
acquia/acquia_content_hub>=0.0.0, <3.6.4, >=3.7.0, <3.7.3
Acquia Acquia Content Hub Drupal<3.6.4
Acquia Acquia Content Hub Drupal>=3.7.0<3.7.3
Event History
Jan 28, 2026
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-14472?
CVE-2025-14472 is classified as moderately critical due to the risk of Cross-Site Request Forgery.
2
How do I fix CVE-2025-14472?
To fix CVE-2025-14472, upgrade the Acquia Content Hub module to version 3.6.4 or 3.7.3 or later.
3
What versions of Acquia Content Hub are affected by CVE-2025-14472?
CVE-2025-14472 affects Acquia Content Hub versions from 0.0.0 before 3.6.4 and from 3.7.0 before 3.7.3.
4
Is CVE-2025-14472 a type of vulnerability that can lead to data breaches?
Yes, CVE-2025-14472 can potentially allow attackers to perform actions on behalf of authenticated users, risking unauthorized access.
5
What type of vulnerability is CVE-2025-14472?
CVE-2025-14472 is a Cross-Site Request Forgery (CSRF) vulnerability.