Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

10.4202420252026

Недавние уязвимости Drupal

Количество 1 966

github логотип

GHSA-39g6-x4x8-5jcm

3 месяца назад

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2qph-q8xw-gv7q

3 месяца назад

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

EPSS: Низкий
github логотип

GHSA-m4wj-hhwj-47qp

3 месяца назад

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-wpp8-fjgf-pwc7

3 месяца назад

Drupal Core Vulnerable to Forceful Browsing

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2025-3057

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-31675

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-31674

3 месяца назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-31673

3 месяца назад

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 4.6
EPSS: Низкий
rocky логотип

RLSA-2025:1215

4 месяца назад

Moderate: tbb security update

EPSS: Средний
rocky логотип

RLSA-2025:1306

4 месяца назад

Moderate: gcc-toolset-13-gcc security update

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-39g6-x4x8-5jcm

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-2qph-q8xw-gv7q

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

0%
Низкий
3 месяца назад
github логотип
GHSA-m4wj-hhwj-47qp

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-wpp8-fjgf-pwc7

Drupal Core Vulnerable to Forceful Browsing

CVSS3: 4.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-3057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 6.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-31675

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-31674

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-31673

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 4.6
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:1215

Moderate: tbb security update

12%
Средний
4 месяца назад
rocky логотип
RLSA-2025:1306

Moderate: gcc-toolset-13-gcc security update

12%
Средний
4 месяца назад

Уязвимостей на страницу


Поделиться