CVE-2025-9549: Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099
Published Oct 10, 2025
·Updated
Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.
Affected Software
4 affected components
Drupal Facets>0.0.0, <2.0.10
Drupal Facets>3.0.0, <3.0.1
Facets Project Facets Drupal<2.0.10
Facets Project Facets Drupal>=3.0.0<3.0.1
Remediation
Patch Available
Event History
Oct 10, 2025
CVE Published
via MITRE·10:24 PM
Data Sourced
via MITRE·10:24 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 27, 57989
Event
via FIRST·09:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9549?
CVE-2025-9549 is categorized as a Missing Authorization vulnerability which can lead to forceful browsing.
2
How do I fix CVE-2025-9549?
To fix CVE-2025-9549, update your Drupal Facets module to version 2.0.10 or 3.0.1 and above.
3
Which versions of Drupal Facets are affected by CVE-2025-9549?
CVE-2025-9549 affects Drupal Facets versions from 0.0.0 before 2.0.10 and from 3.0.0 before 3.0.1.
4
What impact does CVE-2025-9549 have on security?
CVE-2025-9549 allows unauthorized access due to missing authorization checks, which may lead to sensitive data exposure.
5
Is CVE-2025-9549 being actively exploited?
As of the latest updates, there is no publicly reported active exploitation of CVE-2025-9549.