CVE-2025-13083 is a low-severity information disclosure vulnerability in Drupal core versions 7.x, 8.x, 10.x, and 11.x, stemming from the improper use of web browser cache containing sensitive information. An attacker could exploit incorrectly configured access control security levels to gain limited confidentiality impact. This vulnerability has a CVSS score of 3.7 and is not currently listed in CISA's KEV catalog, nor is there any public exploit code available. While there is limited community discussion and media coverage, its EPSS score is very low, indicating a minimal likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 10.4.9CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 10.5.0, < 10.5.6CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.1.9CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 11.2.8CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 7.0, <= 7.103CPE match | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.