Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

10.311.011.110.411.210.52024202520262027

Недавние уязвимости Drupal

Количество 1 987

github логотип

GHSA-mhpg-hpj5-73r2

30 дней назад

Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-h89p-5896-f4q8

30 дней назад

Drupal core allows Content Spoofing

EPSS: Низкий
github логотип

GHSA-m6vv-vcj8-w8m7

30 дней назад

Drupal core allows Object Injection

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-83v7-c2cf-p9c2

30 дней назад

Drupal core allows Forceful Browsing

EPSS: Низкий
nvd логотип

CVE-2025-13083

30 дней назад

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-13082

30 дней назад

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-13081

30 дней назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2025-13080

30 дней назад

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-39g6-x4x8-5jcm

9 месяцев назад

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m4wj-hhwj-47qp

9 месяцев назад

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mhpg-hpj5-73r2

Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels

CVSS3: 3.7
0%
Низкий
30 дней назад
github логотип
GHSA-h89p-5896-f4q8

Drupal core allows Content Spoofing

0%
Низкий
30 дней назад
github логотип
GHSA-m6vv-vcj8-w8m7

Drupal core allows Object Injection

CVSS3: 5.9
0%
Низкий
30 дней назад
github логотип
GHSA-83v7-c2cf-p9c2

Drupal core allows Forceful Browsing

0%
Низкий
30 дней назад
nvd логотип
CVE-2025-13083

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 3.7
0%
Низкий
30 дней назад
nvd логотип
CVE-2025-13082

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 4.3
0%
Низкий
30 дней назад
nvd логотип
CVE-2025-13081

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.9
0%
Низкий
30 дней назад
nvd логотип
CVE-2025-13080

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.3
0%
Низкий
30 дней назад
github логотип
GHSA-39g6-x4x8-5jcm

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-m4wj-hhwj-47qp

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
0%
Низкий
9 месяцев назад

Уязвимостей на страницу


Поделиться