CVE-2026-81162: DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
Published Sep 2, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
Affected Software
2 affected components
Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal>=0.0.0<2.8.1
Dxpr Builder Project Dxpr Builder Drupal<2.8.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DXPR Builder: The Best Editing (AI) Experience for Drupalto a version that resolves this vulnerability.Fixed in 2.8.1Patch SA-CONTRIB-2026-112
Event History
Sep 2, 2026
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which installations are affected?
Drupal sites using DXPR Builder: The Best Editing (AI) Experience for Drupal in versions from 0.0.0 through 2.8.1 are affected.
2
What access does an attacker need to exploit this issue?
The vulnerability is described as allowing forceful browsing. No further prerequisites, authentication requirements, or affected endpoint details are provided.