CVE-2025-13080
PHP vulnerability analysis and mitigation

Overview

CVE-2025-13080 is an Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability in Drupal core that enables Forceful Browsing attacks. It affects Drupal core versions from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, and from 11.2.0 before 11.2.8. The vulnerability was published on November 18, 2025, with patches released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 score of 2.7 (Low) (Drupal Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions), where Drupal core fails to adequately validate or handle unexpected user access attempts, enabling Forceful Browsing. Forceful Browsing is an attack technique where an attacker directly requests URLs or resources that are not linked from the application's normal navigation flow, bypassing intended access controls. No authentication or special privileges are required to exploit this vulnerability, and it is remotely exploitable over the network with low attack complexity. No public technical write-ups or proof-of-concept code have been identified at this time (GitHub Advisory, Drupal Advisory).

Impact

Successful exploitation could allow unauthenticated remote attackers to access restricted pages or functionality within a Drupal site that should be protected by access controls. The primary impact is on integrity (unauthorized access to restricted content or administrative areas), with no direct confidentiality or availability impact according to the CVSS v4.0 scoring. While the individual impact is rated low, exposure of restricted Drupal functionality could facilitate further reconnaissance or privilege escalation depending on site configuration (GitHub Advisory, Drupal Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039% (0.000390), placing it in the 26th percentile for exploitation likelihood within 30 days, indicating a low probability of near-term exploitation (GitHub Advisory).

Mitigation and workarounds

Drupal has released patched versions addressing this vulnerability. Administrators should upgrade to one of the following fixed releases as soon as possible:

  • 10.4.9 or later (for 8.0.0–10.4.x branch)
  • 10.5.6 or later (for 10.5.x branch)
  • 11.1.9 or later (for 11.0.x–11.1.x branch)
  • 11.2.8 or later (for 11.2.x branch)

Additional hardening measures include implementing strict access controls, regularly auditing user permissions, and deploying a Web Application Firewall (WAF) to detect and block unusual browsing patterns (Drupal Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management