The Drupal Symfony Mailer Lite Project maintains a narrowly scoped mail-handling module for Drupal that provides SMTP functionality to email-dependent sites. Its observed vulnerability exposure centers on cross-site request forgery (CSRF) risks in form handling, a class of flaw common to web application plugins where state-changing operations lack adequate request validation.
The number and severity of CVEs published that impact products developed by Drupal Symfony Mailer Lite Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13250HIGH Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 bef | Jan 9, 2025 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drupal Symfony Mailer Lite Project.
Media articles that mention a CVE ID that affects a product developed by Drupal Symfony Mailer Lite Project — matched by CVE ID, not by vendor name.