Lucene search

K

Drupal Project Security Vulnerabilities

cve
cve

CVE-2013-0224

The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP...

7.4AI Score

0.0004EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2013-2247

The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit...

6.9AI Score

0.003EPSS

2022-10-03 04:15 PM
20
cve
cve

CVE-2013-0325

Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin...

5.9AI Score

0.002EPSS

2022-10-03 04:15 PM
22
cve
cve

CVE-2013-2123

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote...

6.8AI Score

0.003EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2013-2197

The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal, when using the login delay option, allows remote attackers to cause a denial of service (CPU consumption) via a large number of failed login...

9AI Score

0.003EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-4139

The Stage File Proxy module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to cause a denial of service (file operations performance degradation and failure) via a large number of...

6.9AI Score

0.004EPSS

2022-10-03 04:14 PM
16
cve
cve

CVE-2013-4272

The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the debugging level is set to 5 or 6, logs the content of submitted forms, which allows context-dependent users to obtain sensitive information such as usernames and...

6.2AI Score

0.002EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-1787

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Simple Corporate theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-1778

Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social...

5.3AI Score

0.001EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-1784

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-1781

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2013-1786

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2013-1779

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-1908

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified...

7AI Score

0.004EPSS

2022-10-03 04:14 PM
23
cve
cve

CVE-2013-1785

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Premium Responsive theme before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2013-1887

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via certain view configuration...

5.5AI Score

0.001EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2015-7943

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified...

6.1CVSS

6.2AI Score

0.005EPSS

2017-10-18 06:29 PM
35
cve
cve

CVE-2015-7876

The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like...

8.3AI Score

0.006EPSS

2015-10-21 02:59 PM
19
cve
cve

CVE-2015-6665

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a"...

5.5AI Score

0.003EPSS

2015-08-24 02:59 PM
36
cve
cve

CVE-2015-5508

Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted...

7.2AI Score

0.002EPSS

2015-08-18 06:00 PM
25
cve
cve

CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted...

6AI Score

0.04EPSS

2014-11-24 03:59 PM
58
cve
cve

CVE-2013-4178

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password...

7AI Score

0.004EPSS

2014-05-29 02:19 PM
17
cve
cve

CVE-2013-4177

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified...

7.2AI Score

0.003EPSS

2014-05-29 02:19 PM
20
cve
cve

CVE-2013-4504

The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted...

6.8AI Score

0.003EPSS

2014-05-13 03:55 PM
14
cve
cve

CVE-2013-1946

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a....

6.8AI Score

0.01EPSS

2014-04-06 04:55 PM
18
cve
cve

CVE-2014-1611

Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name...

5.9AI Score

0.003EPSS

2014-01-30 06:55 PM
14
cve
cve

CVE-2013-4446

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified...

7.8AI Score

0.013EPSS

2013-12-07 08:55 PM
20
cve
cve

CVE-2013-4384

Cross-site scripting (XSS) vulnerability in Google Site Search module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10 for Drupal allows remote attackers to inject arbitrary web script or HTML by causing crafted data to be returned by the Google...

5.8AI Score

0.002EPSS

2013-10-09 02:54 PM
14
cve
cve

CVE-2012-6583

Cross-site scripting (XSS) vulnerability in the Imagemenu module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer imagemenu" permission to inject arbitrary web script or HTML via an image file...

5.5AI Score

0.001EPSS

2013-08-23 03:55 PM
18
cve
cve

CVE-2013-4229

Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web script or HTML via a title in the page...

5.4AI Score

0.001EPSS

2013-08-21 02:55 PM
14
cve
cve

CVE-2013-4230

The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete...

6.4AI Score

0.004EPSS

2013-08-21 02:55 PM
20
cve
cve

CVE-2012-6582

Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain remote attackers to inject arbitrary web script or HTML via a stopforumspam.com API response, which is logged by the...

5.8AI Score

0.003EPSS

2013-08-20 06:14 PM
17
cve
cve

CVE-2013-5315

Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than...

5.8AI Score

0.005EPSS

2013-08-19 11:55 PM
16
cve
cve

CVE-2013-4174

Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flash_width, or (3) flash_height in the scald_flash_scald_prerender function in...

5.8AI Score

0.004EPSS

2013-08-19 11:55 PM
15
cve
cve

CVE-2013-2158

Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown...

7.4AI Score

0.003EPSS

2013-07-01 09:55 PM
21
cve
cve

CVE-2013-2715

Cross-site scripting (XSS) vulnerability in the admin view in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a crafted field...

5.4AI Score

0.001EPSS

2013-03-27 09:55 PM
13
cve
cve

CVE-2013-0259

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject...

5.5AI Score

0.001EPSS

2013-03-27 09:55 PM
21
cve
cve

CVE-2013-1782

Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social...

5.3AI Score

0.001EPSS

2013-03-27 09:55 PM
22
cve
cve

CVE-2013-1783

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2013-03-27 09:55 PM
23
cve
cve

CVE-2013-1780

Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social...

5.3AI Score

0.001EPSS

2013-03-27 09:55 PM
16
cve
cve

CVE-2013-0322

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name...

5.9AI Score

0.003EPSS

2013-03-27 09:55 PM
26
In Wild
cve
cve

CVE-2013-0181

Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error...

6AI Score

0.003EPSS

2013-03-27 09:55 PM
15
cve
cve

CVE-2012-5653

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file...

7AI Score

0.012EPSS

2013-01-03 01:55 AM
35
cve
cve

CVE-2012-5652

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search...

5.9AI Score

0.007EPSS

2013-01-03 01:55 AM
34
cve
cve

CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search...

6AI Score

0.007EPSS

2013-01-03 01:55 AM
38
cve
cve

CVE-2012-5655

The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted...

5.9AI Score

0.006EPSS

2013-01-03 01:55 AM
21
cve
cve

CVE-2012-5585

Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via the Maxpanel...

5.4AI Score

0.001EPSS

2012-12-26 05:55 PM
19
cve
cve

CVE-2012-4468

Cross-site scripting (XSS) vulnerability in the Privatemsg module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a user name in a private...

5.8AI Score

0.002EPSS

2012-11-30 10:55 PM
16
cve
cve

CVE-2012-2084

Cross-site scripting (XSS) vulnerability in the Printer, email and PDF versions module 6.x-1.x before 6.x-1.15 and 7.x-1.x before 7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably the...

5.9AI Score

0.003EPSS

2012-11-22 12:28 PM
25
cve
cve

CVE-2012-4497

Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via a slide...

5.4AI Score

0.001EPSS

2012-11-02 03:55 PM
15
Total number of security vulnerabilities168