CVE-2025-31676: Email Tfa Project Email Tfa
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
Affected products
- Email Tfa Project Email Tfa: before 2.0.3 (fixed in 2.0.3)
Published 2025-03-31. Last modified 2026-06-17.