CVE-2024-13284: Drupalgutenberg Gutenberg

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.

Affected products

  • Drupalgutenberg Gutenberg: before 2.13.0 (fixed in 2.13.0); from 3.0.0, before 3.0.5 (fixed in 3.0.5)

Published 2025-01-09. Last modified 2026-06-17.