Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 975
GHSA-mg24-j67v-7564
The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern.
GHSA-pccg-33v2-pfgp
Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.
GHSA-mqgc-42gw-w5hm
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
GHSA-94p2-4f88-99g7
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
GHSA-836p-6p4j-35cg
Drupal Open Redirect
GHSA-fg5q-r2q5-qmh3
Drupal CRLF injection vulnerability in the drupal_set_header function
GHSA-q3p9-8728-wq7x
Drupal saving user accounts can sometimes grant the user all roles
GHSA-4gh5-3hqj-x3pj
Drupal Form API ignores access restrictions on submit buttons
GHSA-qqxc-cppg-4xp8
Drupal Reflected file download vulnerability
GHSA-pqv4-xgqh-j8vh
Drupal sensitive information disclosure
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-mg24-j67v-7564 The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern. | 0% Низкий | больше 3 лет назад | ||
GHSA-pccg-33v2-pfgp Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons. | 0% Низкий | больше 3 лет назад | ||
GHSA-mqgc-42gw-w5hm The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265. | 73% Высокий | больше 3 лет назад | ||
GHSA-94p2-4f88-99g7 The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | 4% Низкий | больше 3 лет назад | ||
GHSA-836p-6p4j-35cg Drupal Open Redirect | CVSS3: 7.4 | 0% Низкий | больше 3 лет назад | |
GHSA-fg5q-r2q5-qmh3 Drupal CRLF injection vulnerability in the drupal_set_header function | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-q3p9-8728-wq7x Drupal saving user accounts can sometimes grant the user all roles | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-4gh5-3hqj-x3pj Drupal Form API ignores access restrictions on submit buttons | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-qqxc-cppg-4xp8 Drupal Reflected file download vulnerability | CVSS3: 6.4 | 0% Низкий | больше 3 лет назад | |
GHSA-pqv4-xgqh-j8vh Drupal sensitive information disclosure | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу