CVE-2024-13276: File Entity Project File Entity
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.
Affected products
- File Entity Project File Entity: before 7.x-2.39 (fixed in 7.x-2.39)
Published 2025-01-09. Last modified 2026-06-17.