Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

github логотип

GHSA-5vpr-v24w-mmjj

около 4 лет назад

Drupal cross site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wm86-w3cf-h6vm

около 4 лет назад

Drupal external link injection vulnerability

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-585j-5449-mf5m

около 4 лет назад

Drupal cross-site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2p28-5mvp-2j2r

около 4 лет назад

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pqhc-wq43-44m5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

EPSS: Низкий
github логотип

GHSA-9c24-g32g-35rj

около 4 лет назад

Drupal PECL YAML parser unsafe object handling

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-qr75-jf52-qrw8

около 4 лет назад

** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.

EPSS: Низкий
github логотип

GHSA-6f6h-rwhv-q9gg

около 4 лет назад

Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.

EPSS: Низкий
github логотип

GHSA-7ffg-g538-4c8c

около 4 лет назад

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.

EPSS: Низкий
github логотип

GHSA-8q2j-8pc6-8c5r

около 4 лет назад

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-5vpr-v24w-mmjj

Drupal cross site scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-wm86-w3cf-h6vm

Drupal external link injection vulnerability

CVSS3: 4.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-585j-5449-mf5m

Drupal cross-site scripting vulnerability

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2p28-5mvp-2j2r

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-pqhc-wq43-44m5

Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

1%
Низкий
около 4 лет назад
github логотип
GHSA-9c24-g32g-35rj

Drupal PECL YAML parser unsafe object handling

CVSS3: 9.8
20%
Средний
около 4 лет назад
github логотип
GHSA-qr75-jf52-qrw8

** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6f6h-rwhv-q9gg

Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7ffg-g538-4c8c

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-8q2j-8pc6-8c5r

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться