Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.110.411.210.5202420252026

Недавние уязвимости Drupal

Количество 1 975

github логотип

GHSA-mg24-j67v-7564

больше 3 лет назад

The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern.

EPSS: Низкий
github логотип

GHSA-pccg-33v2-pfgp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

EPSS: Низкий
github логотип

GHSA-mqgc-42gw-w5hm

больше 3 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

EPSS: Высокий
github логотип

GHSA-94p2-4f88-99g7

больше 3 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

EPSS: Низкий
github логотип

GHSA-836p-6p4j-35cg

больше 3 лет назад

Drupal Open Redirect

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-fg5q-r2q5-qmh3

больше 3 лет назад

Drupal CRLF injection vulnerability in the drupal_set_header function

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-q3p9-8728-wq7x

больше 3 лет назад

Drupal saving user accounts can sometimes grant the user all roles

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4gh5-3hqj-x3pj

больше 3 лет назад

Drupal Form API ignores access restrictions on submit buttons

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qqxc-cppg-4xp8

больше 3 лет назад

Drupal Reflected file download vulnerability

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-pqv4-xgqh-j8vh

больше 3 лет назад

Drupal sensitive information disclosure

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-mg24-j67v-7564

The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-pccg-33v2-pfgp

Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mqgc-42gw-w5hm

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

73%
Высокий
больше 3 лет назад
github логотип
GHSA-94p2-4f88-99g7

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-836p-6p4j-35cg

Drupal Open Redirect

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fg5q-r2q5-qmh3

Drupal CRLF injection vulnerability in the drupal_set_header function

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q3p9-8728-wq7x

Drupal saving user accounts can sometimes grant the user all roles

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4gh5-3hqj-x3pj

Drupal Form API ignores access restrictions on submit buttons

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qqxc-cppg-4xp8

Drupal Reflected file download vulnerability

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pqv4-xgqh-j8vh

Drupal sensitive information disclosure

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться