CVE-2024-13276: File Entity Project File Entity

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.

Affected products

Published 2025-01-09. Last modified 2026-06-17.