Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

ubuntu логотип

CVE-2018-9861

почти 8 лет назад

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-7600

почти 8 лет назад

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2018-7600

почти 8 лет назад

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x be ...

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2018-7600

почти 8 лет назад

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

CVSS3: 9.8
EPSS: Критический
fstec логотип

BDU:2021-00549

почти 8 лет назад

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код и перехватить контроль над сайтом

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2017-6932

почти 8 лет назад

Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2017-6932

почти 8 лет назад

Drupal core 7.x versions before 7.57 has an external link injection vu ...

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2017-6931

почти 8 лет назад

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but does not harden against other such bypasses. This vulnerability can be mitigated by disabling the Settings Tray module.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-6931

почти 8 лет назад

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray modul ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-6930

почти 8 лет назад

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2018-9861

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.

CVSS3: 6.1
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-7600

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

CVSS3: 9.8
94%
Критический
почти 8 лет назад
debian логотип
CVE-2018-7600

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x be ...

CVSS3: 9.8
94%
Критический
почти 8 лет назад
ubuntu логотип
CVE-2018-7600

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

CVSS3: 9.8
94%
Критический
почти 8 лет назад
fstec логотип
BDU:2021-00549

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код и перехватить контроль над сайтом

CVSS3: 9.8
94%
Критический
почти 8 лет назад
nvd логотип
CVE-2017-6932

Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.

CVSS3: 4.7
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-6932

Drupal core 7.x versions before 7.57 has an external link injection vu ...

CVSS3: 4.7
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-6931

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but does not harden against other such bypasses. This vulnerability can be mitigated by disabling the Settings Tray module.

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-6931

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray modul ...

CVSS3: 6.5
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-6930

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().

CVSS3: 8.1
0%
Низкий
почти 8 лет назад

Уязвимостей на страницу


Поделиться