CVE-2025-13985: Ithom Entity Share

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.

Affected products

  • Ithom Entity Share: before 3.13.0 (fixed in 3.13.0)

Published 2026-01-28. Last modified 2026-06-17.