Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 988
GHSA-8jj2-x2gc-ggm7
Drupal Core Cross-site scripting vulnerability
GHSA-wxqp-jwc9-g39x
Drupal Core Access bypass vulnerability
GHSA-x72f-ggjw-v5xh
Drupal Core Arbitrary PHP code execution vulnerability
GHSA-cmmh-8mwp-gq5p
Drupal Cross Site Scripting (XSS) vulnerability
GHSA-6grv-hw8g-4gfm
PrestaShop Cross-site Scripting vulnerability
GHSA-57vg-4hw3-gq38
Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-gg66-rc85-hvpw
Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authentication of unspecified victims to delete OpenID identities via unknown vectors.
GHSA-cggr-42mf-4mqj
Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.
GHSA-fpf8-6xj4-hr2q
Cross-site scripting (XSS) vulnerability in the AddThis Button module 5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote authenticated users, with administer addthis privileges, to inject arbitrary web script or HTML via unspecified vectors.
GHSA-6x6x-fpgp-99vx
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1358.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-8jj2-x2gc-ggm7 Drupal Core Cross-site scripting vulnerability | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-wxqp-jwc9-g39x Drupal Core Access bypass vulnerability | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-x72f-ggjw-v5xh Drupal Core Arbitrary PHP code execution vulnerability | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-cmmh-8mwp-gq5p Drupal Cross Site Scripting (XSS) vulnerability | CVSS3: 5.4 | 41% Средний | больше 3 лет назад | |
GHSA-6grv-hw8g-4gfm PrestaShop Cross-site Scripting vulnerability | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-57vg-4hw3-gq38 Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-gg66-rc85-hvpw Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authentication of unspecified victims to delete OpenID identities via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-cggr-42mf-4mqj Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input. | 0% Низкий | больше 3 лет назад | ||
GHSA-fpf8-6xj4-hr2q Cross-site scripting (XSS) vulnerability in the AddThis Button module 5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote authenticated users, with administer addthis privileges, to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-6x6x-fpgp-99vx Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1358. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу