Lucene search

K

Drupal Security Vulnerabilities

cve
cve

CVE-2013-4228

The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via ...

4.3CVSS

4.4AI Score

0.002EPSS

2020-02-18 07:15 PM
65
cve
cve

CVE-2013-6385

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-spec...

7.3AI Score

0.056EPSS

2013-12-07 09:55 PM
29
cve
cve

CVE-2013-6386

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

6.5AI Score

0.004EPSS

2013-12-07 09:55 PM
39
cve
cve

CVE-2013-6387

Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.

5.1AI Score

0.001EPSS

2013-12-24 08:55 PM
29
cve
cve

CVE-2013-6388

Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

5.4AI Score

0.002EPSS

2013-12-24 08:55 PM
27
cve
cve

CVE-2013-6389

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

6.5AI Score

0.002EPSS

2013-12-07 09:55 PM
37
cve
cve

CVE-2013-7407

Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

7.3AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2014-1475

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

6.3AI Score

0.007EPSS

2014-01-24 06:55 PM
34
cve
cve

CVE-2014-1476

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.

5.5AI Score

0.002EPSS

2014-01-24 06:55 PM
39
cve
cve

CVE-2014-1607

Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE...

5.8AI Score

0.002EPSS

2014-01-26 08:55 PM
22
cve
cve

CVE-2014-2983

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

5.8AI Score

0.002EPSS

2014-04-23 03:55 PM
40
cve
cve

CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

7AI Score

0.975EPSS

2014-10-16 12:55 AM
154
2
cve
cve

CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

5.9AI Score

0.001EPSS

2022-10-03 04:20 PM
35
cve
cve

CVE-2014-5020

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

5.7AI Score

0.001EPSS

2022-10-03 04:20 PM
32
cve
cve

CVE-2014-5021

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

5.7AI Score

0.001EPSS

2022-10-03 04:20 PM
39
cve
cve

CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

5.8AI Score

0.001EPSS

2022-10-03 04:20 PM
36
cve
cve

CVE-2014-5170

The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.

9.8CVSS

9.7AI Score

0.02EPSS

2018-03-29 06:29 PM
17
2
cve
cve

CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a craft...

6.8AI Score

0.436EPSS

2014-08-18 11:15 AM
110
cve
cve

CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability...

6.1AI Score

0.929EPSS

2014-08-18 11:15 AM
111
cve
cve

CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

6.7AI Score

0.005EPSS

2014-09-30 02:55 PM
102
cve
cve

CVE-2014-7869

Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via unspecified vectors.

5.4AI Score

0.001EPSS

2022-10-03 04:20 PM
21
cve
cve

CVE-2014-7870

Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom search" permission to inject arbitrary web script or HTML via the "Label text" field to admin/config/sear...

5.5AI Score

0.001EPSS

2022-10-03 04:20 PM
22
cve
cve

CVE-2014-7978

Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.

5.3AI Score

0.001EPSS

2014-10-08 06:55 PM
15
cve
cve

CVE-2014-7979

Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.

5.3AI Score

0.001EPSS

2014-10-08 06:55 PM
15
cve
cve

CVE-2014-7980

Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecifie...

5.6AI Score

0.001EPSS

2022-10-03 04:20 PM
20
cve
cve

CVE-2014-8075

Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.

5.5AI Score

0.001EPSS

2014-10-09 02:55 PM
21
cve
cve

CVE-2014-8076

Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright information.

5.3AI Score

0.001EPSS

2014-10-09 02:55 PM
20
cve
cve

CVE-2014-8077

Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to font family CSS property.

5.4AI Score

0.001EPSS

2014-10-09 02:55 PM
16
cve
cve

CVE-2014-8078

Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors re...

5.4AI Score

0.001EPSS

2014-10-09 02:55 PM
19
cve
cve

CVE-2014-8079

Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to header background setting.

5.3AI Score

0.001EPSS

2014-10-09 02:55 PM
16
cve
cve

CVE-2014-8296

Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.9AI Score

0.002EPSS

2014-10-16 02:55 PM
16
cve
cve

CVE-2014-8734

The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors.

6.4AI Score

0.001EPSS

2014-11-12 04:55 PM
24
cve
cve

CVE-2014-8743

Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.

5.5AI Score

0.001EPSS

2014-10-13 06:55 PM
17
cve
cve

CVE-2014-8744

Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrary web script or HTML via an image title.

5.5AI Score

0.001EPSS

2014-10-13 06:55 PM
20
cve
cve

CVE-2014-8745

Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.

5.4AI Score

0.001EPSS

2014-10-13 06:55 PM
17
cve
cve

CVE-2014-8746

Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.

5.3AI Score

0.001EPSS

2014-10-13 06:55 PM
22
cve
cve

CVE-2014-8747

Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content creation and activity stream messages.

5.8AI Score

0.003EPSS

2014-10-13 06:55 PM
19
cve
cve

CVE-2014-8748

Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.

5.4AI Score

0.001EPSS

2022-10-03 04:20 PM
17
cve
cve

CVE-2014-8765

Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and return the results t...

5.4AI Score

0.001EPSS

2022-10-03 04:20 PM
24
cve
cve

CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

6AI Score

0.007EPSS

2014-11-24 03:59 PM
41
cve
cve

CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

6AI Score

0.04EPSS

2014-11-24 03:59 PM
58
cve
cve

CVE-2015-2559

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

6AI Score

0.001EPSS

2015-03-25 02:59 PM
42
cve
cve

CVE-2015-2749

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

6.1CVSS

6.2AI Score

0.003EPSS

2017-09-13 04:29 PM
39
cve
cve

CVE-2015-2750

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

6.1CVSS

6.1AI Score

0.003EPSS

2017-09-13 04:29 PM
36
2
cve
cve

CVE-2015-3231

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

5.9AI Score

0.002EPSS

2015-06-22 07:59 PM
44
cve
cve

CVE-2015-3232

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

6.4AI Score

0.004EPSS

2015-06-22 07:59 PM
36
cve
cve

CVE-2015-3233

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

6AI Score

0.005EPSS

2015-06-22 07:59 PM
39
cve
cve

CVE-2015-3234

The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.

6.4AI Score

0.005EPSS

2015-06-22 07:59 PM
35
cve
cve

CVE-2015-6658

Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.

5.4AI Score

0.003EPSS

2015-08-24 02:59 PM
34
cve
cve

CVE-2015-6659

SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

8.2AI Score

0.006EPSS

2015-08-24 02:59 PM
36
Total number of security vulnerabilities411