CVE-2025-9551Medium· 6.5▾ SunlitImproper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before 7.X-2.5.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before 7.X-2.5.
protected_pages < 8.x-1.8Upgrade past the affected range:
protected_pages 8.x-1.8Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12547Low· 3.7A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1
CVE-2025-66204High· 8.1WBCE CMS is a content management system
CVE-2026-107638Medium· 6.8pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits
CVE-2025-11441Low· 3.7A vulnerability was identified in JhumanJ OpnForm up to 1.9.3
CVE-2026-30959Medium· 5.0OneUptime is a solution for monitoring and managing online services
CVE-2026-105866Medium· 6.9Payload is a free and open source headless content management system