Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9037 | Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability |
Github GHSA |
GHSA-jh66-rjx8-8qqc | Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-008 |
|
Mon, 02 Jun 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Matomo Analytics Project
Matomo Analytics Project matomo Analytics |
|
| CPEs | cpe:2.3:a:matomo_analytics_project:matomo_analytics:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Matomo Analytics Project
Matomo Analytics Project matomo Analytics |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0. | |
| Title | Matomo Analytics - Moderately critical - Cross site request forgery - SA-CONTRIB-2025-008 | |
| Weaknesses | CWE-352 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:38:13.666Z
Reserved: 2025-03-31T21:30:04.616Z
Link: CVE-2025-31680
Updated: 2025-04-29T15:38:02.522Z
Status : Analyzed
Published: 2025-03-31T22:15:20.550
Modified: 2025-06-02T20:00:35.477
Link: CVE-2025-31680
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA