Lucene search

K

Drupal Project Security Vulnerabilities

cve
cve

CVE-2010-5276

The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in...

6.7AI Score

0.001EPSS

2022-10-03 04:21 PM
17
cve
cve

CVE-2010-5275

Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.9AI Score

0.001EPSS

2022-10-03 04:21 PM
23
cve
cve

CVE-2015-8095

The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL...

6.4AI Score

0.002EPSS

2022-10-03 04:16 PM
17
cve
cve

CVE-2012-2116

Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping...

7.5AI Score

0.002EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2012-2302

Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive information via unspecified...

6.4AI Score

0.004EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2012-2064

Cross-site scripting (XSS) vulnerability in theme/views_lang_switch.theme.inc in the Views Language Switcher module before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q...

5.9AI Score

0.002EPSS

2022-10-03 04:15 PM
17
cve
cve

CVE-2012-2096

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote...

6.8AI Score

0.005EPSS

2022-10-03 04:15 PM
24
cve
cve

CVE-2012-2300

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal allow remote authenticated users with the administer product classes permission to inject arbitrary web script or HTML via unspecified...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2012-2299

The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the...

6AI Score

0.0004EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2012-2065

Cross-site scripting (XSS) vulnerability in the Language Icons module 6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with administer languages permissions to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:15 PM
19
cve
cve

CVE-2012-4488

The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote attackers to read node or user results via the location search...

6.9AI Score

0.002EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2012-4475

The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote attackers to edit an arbitrary user's questions and answers via unspecified...

7AI Score

0.002EPSS

2022-10-03 04:15 PM
18
cve
cve

CVE-2012-2083

Cross-site scripting (XSS) vulnerability in the fusion_core_preprocess_page function in fusion_core/template.php in the Fusion module before 6.x-1.13 for Drupal allows remote attackers to inject arbitrary web script or HTML via the q...

5.9AI Score

0.002EPSS

2022-10-03 04:15 PM
17
cve
cve

CVE-2012-4554

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS...

6.4AI Score

0.166EPSS

2022-10-03 04:15 PM
28
cve
cve

CVE-2012-4483

The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain...

6.4AI Score

0.002EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2012-4494

The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging...

7.3AI Score

0.001EPSS

2022-10-03 04:15 PM
15
cve
cve

CVE-2012-4553

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient...

7.3AI Score

0.004EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2012-5557

The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain...

6.7AI Score

0.001EPSS

2022-10-03 04:15 PM
26
cve
cve

CVE-2012-5539

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be...

6.6AI Score

0.001EPSS

2022-10-03 04:15 PM
19
cve
cve

CVE-2012-5541

Cross-site scripting (XSS) vulnerability in the Twitter Pull module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.0-rc3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "data coming from...

5.8AI Score

0.001EPSS

2022-10-03 04:15 PM
17
cve
cve

CVE-2012-5556

Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to hijack the authentication of arbitrary users via unknown...

7.5AI Score

0.001EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2012-5543

The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source...

7AI Score

0.002EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2012-5537

The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by...

6.8AI Score

0.004EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2012-5233

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2012-5569

Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email...

5.8AI Score

0.001EPSS

2022-10-03 04:15 PM
17
2
cve
cve

CVE-2012-5654

The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1)...

6.4AI Score

0.002EPSS

2022-10-03 04:15 PM
18
cve
cve

CVE-2012-1643

The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers to modify access permissions via unspecified...

6.9AI Score

0.004EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2012-1638

SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified...

8.1AI Score

0.003EPSS

2022-10-03 04:15 PM
24
cve
cve

CVE-2012-1654

Multiple cross-site scripting (XSS) vulnerabilities in the Data module 6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal allow remote authenticated users with the administer data tables permission to inject arbitrary web script or HTML via the title parameter in (1)...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2012-1632

Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
19
cve
cve

CVE-2012-1641

The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via...

7.5AI Score

0.01EPSS

2022-10-03 04:15 PM
18
cve
cve

CVE-2012-1060

Multiple cross-site scripting (XSS) vulnerabilities in revisioning_theme.inc in the Taxonomy module in the Revisioning module 6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) tags or...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2012-1645

The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading...

7.1AI Score

0.003EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2012-1636

Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified...

7.3AI Score

0.001EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2012-1642

includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken links, which allows remote attackers to obtain sensitive information via unspecified...

6.4AI Score

0.003EPSS

2022-10-03 04:15 PM
17
cve
cve

CVE-2012-1627

Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
26
cve
cve

CVE-2013-0182

The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary...

6.9AI Score

0.002EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2013-0227

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2013-0205

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown...

7.5AI Score

0.001EPSS

2022-10-03 04:15 PM
17
cve
cve

CVE-2013-0321

Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name...

5.9AI Score

0.001EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2013-0317

Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete...

5.9AI Score

0.001EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2013-0320

Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified...

7.3AI Score

0.002EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2013-0323

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author...

5.9AI Score

0.002EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2013-0324

Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
19
cve
cve

CVE-2013-0206

Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a...

7.6AI Score

0.01EPSS

2022-10-03 04:15 PM
18
cve
cve

CVE-2013-0258

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the...

6.9AI Score

0.004EPSS

2022-10-03 04:15 PM
28
cve
cve

CVE-2013-0207

Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown...

7.3AI Score

0.001EPSS

2022-10-03 04:15 PM
24
cve
cve

CVE-2013-0318

The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified...

6.9AI Score

0.004EPSS

2022-10-03 04:15 PM
29
cve
cve

CVE-2013-0225

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship...

5.4AI Score

0.001EPSS

2022-10-03 04:15 PM
17
cve
cve

CVE-2013-0319

Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service...

5.9AI Score

0.002EPSS

2022-10-03 04:15 PM
20
Total number of security vulnerabilities168