Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

github логотип

GHSA-6g9h-6v79-w4pc

около 4 лет назад

Drupal Users without "Administer comments" can set comment visibility on nodes they can edit

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vhg8-x858-7wq6

около 4 лет назад

Drupal Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-fmqh-2j2x-vgp3

около 4 лет назад

Drupal Unprivileged access to config export

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rfxx-gxwc-923c

около 4 лет назад

Drupal Views can allow unauthorized users to see Statistics information

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-frqf-9qr4-6vxf

около 4 лет назад

Drupal Saving user accounts can sometimes grant the user all roles

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-jpj8-49hr-wcwv

около 4 лет назад

Drupal Denial of service via transliterate mechanism

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-98w5-wqp9-w466

около 4 лет назад

Drupal Incorrect cache context on password reset page

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rcwp-vp94-qpq4

около 4 лет назад

The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.

EPSS: Низкий
github логотип

GHSA-p68q-6jc7-9w28

около 4 лет назад

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-pfc2-6vvp-c5mq

около 4 лет назад

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-6g9h-6v79-w4pc

Drupal Users without "Administer comments" can set comment visibility on nodes they can edit

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-vhg8-x858-7wq6

Drupal Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-fmqh-2j2x-vgp3

Drupal Unprivileged access to config export

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-rfxx-gxwc-923c

Drupal Views can allow unauthorized users to see Statistics information

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-frqf-9qr4-6vxf

Drupal Saving user accounts can sometimes grant the user all roles

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-jpj8-49hr-wcwv

Drupal Denial of service via transliterate mechanism

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-98w5-wqp9-w466

Drupal Incorrect cache context on password reset page

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-rcwp-vp94-qpq4

The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.

2%
Низкий
около 4 лет назад
github логотип
GHSA-p68q-6jc7-9w28

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-pfc2-6vvp-c5mq

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться