CVE-2025-10930: 2bits Currency

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0.

Affected products

  • 2bits Currency: before 8.x-3.5 (fixed in 8.x-3.5)

Published 2025-10-30. Last modified 2026-10-08.