CVE-2025-31680: Matomo Analytics - Moderately critical - Cross site request forgery - SA-CONTRIB-2025-008
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery. This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31680?
CVE-2025-31680 is a critical Cross-Site Request Forgery (CSRF) vulnerability in the Matomo Analytics extension for Drupal.
How do I fix CVE-2025-31680?
To fix CVE-2025-31680, upgrade Matomo Analytics to version 1.24.0 or later.
Which versions of Matomo Analytics are affected by CVE-2025-31680?
CVE-2025-31680 affects Matomo Analytics versions from 0.0.0 up to but not including 1.24.0.
What impact can CVE-2025-31680 have on my website?
CVE-2025-31680 can allow attackers to perform unauthorized actions on behalf of users who are logged in to the Drupal site.
Is there a workaround for CVE-2025-31680 if I cannot upgrade?
There are no known workarounds for CVE-2025-31680; upgrading to a patched version is strongly recommended.