Fourkitchens maintains a focused set of Drupal-related modules and extensions, including Block Class, ED Readmore, and Recent Comments, that extend functionality for content management and display. The recurring vulnerability signal centers on cross-site scripting flaws arising from improper input neutralization in web page generation, a characteristic weakness in user-facing content modules. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fourkitchens over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3144MEDIUM Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permissio | Apr 15, 2016 | 5.4 | 20 | NO | NO |
CVE-2025-3902MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block | Apr 23, 2025 | 6.1 | 18 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Read More Link module 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users with the access administration pages permi | Sep 18, 2012 | 2.1 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inj | Sep 18, 2012 | 2.1 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary | Mar 25, 2010 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fourkitchens.
Media articles that mention a CVE ID that affects a product developed by Fourkitchens — matched by CVE ID, not by vendor name.