Lucene search

K

Drupal Security Vulnerabilities

cve
cve

CVE-2009-4066

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to...

7.3AI Score

0.003EPSS

2009-11-24 02:30 AM
29
cve
cve

CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web scri...

5.3AI Score

0.001EPSS

2009-12-21 04:30 PM
22
cve
cve

CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu ad...

5.2AI Score

0.001EPSS

2009-12-21 04:30 PM
24
cve
cve

CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in...

5.5AI Score

0.001EPSS

2009-12-21 04:30 PM
21
cve
cve

CVE-2009-4602

Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.9AI Score

0.001EPSS

2022-10-03 04:24 PM
25
cve
cve

CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

6.1CVSS

5.9AI Score

0.002EPSS

2019-11-07 06:15 PM
54
cve
cve

CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

6.1CVSS

6.3AI Score

0.003EPSS

2019-11-06 06:15 PM
66
3
cve
cve

CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigat...

4.8CVSS

5.3AI Score

0.001EPSS

2019-11-07 07:15 PM
58
cve
cve

CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

6.5CVSS

6.4AI Score

0.001EPSS

2019-11-07 07:15 PM
49
cve
cve

CVE-2010-3022

Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths i...

5.5AI Score

0.001EPSS

2010-08-16 08:00 PM
25
cve
cve

CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

6.9AI Score

0.005EPSS

2022-10-03 04:20 PM
39
cve
cve

CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar na...

6.2AI Score

0.002EPSS

2022-10-03 04:20 PM
28
cve
cve

CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

6.2AI Score

0.001EPSS

2022-10-03 04:20 PM
46
cve
cve

CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and ...

5.3AI Score

0.001EPSS

2022-10-03 04:20 PM
31
cve
cve

CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

7AI Score

0.005EPSS

2022-10-03 04:20 PM
31
cve
cve

CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

7AI Score

0.005EPSS

2022-10-03 04:20 PM
26
cve
cve

CVE-2010-5312

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

6.1CVSS

6AI Score

0.002EPSS

2014-11-24 04:59 PM
143
2
cve
cve

CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

6.5AI Score

0.014EPSS

2011-07-27 02:55 AM
26
cve
cve

CVE-2011-2714

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

6.1CVSS

6AI Score

0.001EPSS

2020-01-14 10:15 PM
55
cve
cve

CVE-2011-2715

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

9.8CVSS

9.7AI Score

0.002EPSS

2020-01-14 10:15 PM
57
cve
cve

CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access...

7.5CVSS

7.5AI Score

0.004EPSS

2019-11-15 05:15 PM
72
cve
cve

CVE-2011-3373

Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-sit...

6.1CVSS

5.8AI Score

0.002EPSS

2019-11-25 11:15 PM
49
cve
cve

CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

7.2AI Score

0.003EPSS

2022-10-03 04:15 PM
28
cve
cve

CVE-2011-4560

Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition.

5.4AI Score

0.001EPSS

2011-11-28 09:55 PM
18
cve
cve

CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

6AI Score

0.004EPSS

2013-10-28 10:55 PM
30
cve
cve

CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit...

7AI Score

0.001EPSS

2013-10-28 10:55 PM
34
cve
cve

CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

6.2AI Score

0.001EPSS

2013-10-28 10:55 PM
24
cve
cve

CVE-2012-1588

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

6.2AI Score

0.01EPSS

2012-10-01 12:55 AM
19
cve
cve

CVE-2012-1589

Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.

6.6AI Score

0.004EPSS

2012-05-18 08:55 PM
28
cve
cve

CVE-2012-1590

The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

5.8AI Score

0.003EPSS

2012-10-01 12:55 AM
33
cve
cve

CVE-2012-1591

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.

6.5AI Score

0.006EPSS

2012-10-01 12:55 AM
21
cve
cve

CVE-2012-1637

Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.

4.8CVSS

5AI Score

0.001EPSS

2019-11-21 11:15 PM
90
cve
cve

CVE-2012-1646

Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.

5.5AI Score

0.003EPSS

2012-09-25 11:55 PM
25
cve
cve

CVE-2012-2078

Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.

4.8CVSS

5AI Score

0.001EPSS

2019-11-21 11:15 PM
78
cve
cve

CVE-2012-2079

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

8.8CVSS

8.7AI Score

0.001EPSS

2019-11-22 12:15 AM
98
cve
cve

CVE-2012-2153

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

6AI Score

0.002EPSS

2012-10-01 12:55 AM
23
cve
cve

CVE-2012-2298

Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks."

5.8AI Score

0.005EPSS

2012-08-14 10:55 PM
19
cve
cve

CVE-2012-2306

SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

8.7AI Score

0.002EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2012-2339

Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "taxonomy information."

5.8AI Score

0.004EPSS

2012-05-21 08:55 PM
21
cve
cve

CVE-2012-2922

The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.

6.8AI Score

0.007EPSS

2012-05-21 10:55 PM
45
cve
cve

CVE-2012-4553

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

7.3AI Score

0.004EPSS

2022-10-03 04:15 PM
27
cve
cve

CVE-2012-4554

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

6.4AI Score

0.166EPSS

2022-10-03 04:15 PM
28
cve
cve

CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

6AI Score

0.007EPSS

2013-01-03 01:55 AM
38
cve
cve

CVE-2012-5652

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

5.9AI Score

0.007EPSS

2013-01-03 01:55 AM
34
cve
cve

CVE-2012-5653

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

7AI Score

0.012EPSS

2013-01-03 01:55 AM
35
cve
cve

CVE-2013-0244

Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are use...

7.4AI Score

0.003EPSS

2014-01-19 05:16 PM
36
cve
cve

CVE-2013-0245

The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles an...

6AI Score

0.002EPSS

2013-07-16 06:55 PM
37
cve
cve

CVE-2013-0246

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

6.6AI Score

0.003EPSS

2022-10-03 04:15 PM
24
cve
cve

CVE-2013-0316

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

6.5AI Score

0.002EPSS

2022-10-03 04:15 PM
37
cve
cve

CVE-2013-4226

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.

6.5CVSS

6.3AI Score

0.002EPSS

2020-02-18 07:15 PM
70
Total number of security vulnerabilities411