CVE-2016-9451: Drupal
Medium severity, CVSS 6.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
Affected products
- Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.10 only; …
Published 2016-11-25. Last modified 2026-06-17.