CVE-2025-8361: Config Pages Project Config Pages
High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: from 0.0.0 before 2.18.0.
Affected products
- Config Pages Project Config Pages: before 2.18.0 (fixed in 2.18.0)
Published 2025-08-15. Last modified 2026-08-10.