Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.110.411.210.5202420252026

Недавние уязвимости Drupal

Количество 1 975

github логотип

GHSA-5746-cvmj-7x62

больше 3 лет назад

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6chq-45fq-p3pv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via a slide URL.

EPSS: Низкий
github логотип

GHSA-64rw-f427-xf6w

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject arbitrary web script or HTML via the status labels parameter.

EPSS: Низкий
github логотип

GHSA-gx7f-xhxg-cvr3

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.

EPSS: Низкий
github логотип

GHSA-5vpr-v24w-mmjj

больше 3 лет назад

Drupal cross site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wm86-w3cf-h6vm

больше 3 лет назад

Drupal external link injection vulnerability

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-585j-5449-mf5m

больше 3 лет назад

Drupal cross-site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2p28-5mvp-2j2r

больше 3 лет назад

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pqhc-wq43-44m5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

EPSS: Низкий
github логотип

GHSA-9c24-g32g-35rj

больше 3 лет назад

Drupal PECL YAML parser unsafe object handling

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-5746-cvmj-7x62

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-6chq-45fq-p3pv

Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via a slide URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-64rw-f427-xf6w

Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject arbitrary web script or HTML via the status labels parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-gx7f-xhxg-cvr3

Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5vpr-v24w-mmjj

Drupal cross site scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wm86-w3cf-h6vm

Drupal external link injection vulnerability

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-585j-5449-mf5m

Drupal cross-site scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p28-5mvp-2j2r

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pqhc-wq43-44m5

Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9c24-g32g-35rj

Drupal PECL YAML parser unsafe object handling

CVSS3: 9.8
67%
Средний
больше 3 лет назад

Уязвимостей на страницу


Поделиться