Protected Pages Project develops a focused web application designed to restrict access through authentication controls. The vulnerability signal centers on the core mechanism—improper restriction of excessive authentication attempts—reflecting a weakness in the rate-limiting and account-protection logic that guards the product's access layer. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Protected Pages Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9551MEDIUM Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, fr | Oct 10, 2025 | 6.5 | 22 | NO | NO |
CVE-2014-9024HIGH The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path. | Nov 20, 2014 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Protected Pages Project.
Media articles that mention a CVE ID that affects a product developed by Protected Pages Project — matched by CVE ID, not by vendor name.