Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

github логотип

GHSA-5gv4-95g8-gfc6

около 4 лет назад

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

EPSS: Низкий
github логотип

GHSA-j9pq-x44j-6p86

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.

EPSS: Низкий
github логотип

GHSA-vfw4-2ffw-69gw

около 4 лет назад

The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

EPSS: Низкий
github логотип

GHSA-wgpj-2628-3c8v

около 4 лет назад

Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu.

EPSS: Низкий
github логотип

GHSA-jp2q-xrh4-4hph

около 4 лет назад

SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

EPSS: Низкий
github логотип

GHSA-fvm9-qc7j-544c

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.

EPSS: Низкий
github логотип

GHSA-p745-347h-hjfw

около 4 лет назад

Drupal sensitive information disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-66gr-xrcf-8jpq

около 4 лет назад

Drupal Open Redirect

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-v6gx-89ww-chv2

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a user.

EPSS: Низкий
github логотип

GHSA-gxxq-fhc7-3jv9

около 4 лет назад

Drupal Cross-Site Request Forgery (CSRF)

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-5gv4-95g8-gfc6

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

2%
Низкий
около 4 лет назад
github логотип
GHSA-j9pq-x44j-6p86

Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.

2%
Низкий
около 4 лет назад
github логотип
GHSA-vfw4-2ffw-69gw

The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

1%
Низкий
около 4 лет назад
github логотип
GHSA-wgpj-2628-3c8v

Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu.

3%
Низкий
около 4 лет назад
github логотип
GHSA-jp2q-xrh4-4hph

SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

3%
Низкий
около 4 лет назад
github логотип
GHSA-fvm9-qc7j-544c

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.

3%
Низкий
около 4 лет назад
github логотип
GHSA-p745-347h-hjfw

Drupal sensitive information disclosure

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-66gr-xrcf-8jpq

Drupal Open Redirect

CVSS3: 6.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-v6gx-89ww-chv2

Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gxxq-fhc7-3jv9

Drupal Cross-Site Request Forgery (CSRF)

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться