Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.110.411.210.5202420252026

Недавние уязвимости Drupal

Количество 1 975

github логотип

GHSA-vp7c-82j8-vfqp

больше 3 лет назад

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."

EPSS: Низкий
github логотип

GHSA-367f-3f3f-6cpx

больше 3 лет назад

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

EPSS: Низкий
github логотип

GHSA-3gx6-h57h-rm27

больше 3 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-9m8p-564h-5p6w

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.

EPSS: Низкий
github логотип

GHSA-cfc7-w9hw-779w

больше 3 лет назад

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

EPSS: Высокий
github логотип

GHSA-p4jq-p7qf-pw64

больше 3 лет назад

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-f9cm-c972-9975

больше 3 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

EPSS: Критический
github логотип

GHSA-8wgj-6wx8-h5hq

больше 3 лет назад

Symfony HTTP Foundation web cache poisoning

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x636-25mv-6hv8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

EPSS: Низкий
github логотип

GHSA-mw78-v8j9-2m24

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-vp7c-82j8-vfqp

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-367f-3f3f-6cpx

The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting to be approved.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gx6-h57h-rm27

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
94%
Критический
больше 3 лет назад
github логотип
GHSA-9m8p-564h-5p6w

Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cfc7-w9hw-779w

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

77%
Высокий
больше 3 лет назад
github логотип
GHSA-p4jq-p7qf-pw64

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f9cm-c972-9975

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

94%
Критический
больше 3 лет назад
github логотип
GHSA-8wgj-6wx8-h5hq

Symfony HTTP Foundation web cache poisoning

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-x636-25mv-6hv8

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-mw78-v8j9-2m24

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться