CVE-2026-81162 PUBLISHED

DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

Product Status

Vendor Drupal
Product DXPR Builder: The Best Editing (AI) Experience for Drupal
Versions
  • affected from 0.0.0 to 2.8.1 (excl.)

Credits

  • jurriaanroelofs finder
  • jurriaanroelofs remediation developer
  • Greg Knaddison (greggles) coordinator
  • Juraj Nemec (poker10) coordinator
  • Jess (xjm) coordinator

References

Problem Types

  • CWE-201 Insertion of Sensitive Information Into Sent Data CWE

Impacts

  • CAPEC-87 Forceful Browsing