Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 029
GHSA-26gr-c7rc-wwqj
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
GHSA-hqq6-wqq7-jgjq
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.
GHSA-7fh9-933g-885p
Drupal Core Remote Code Execution Vulnerability
GHSA-g78h-pf65-46rv
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)
GHSA-7ffh-cjvg-fpr4
Drupal Settings Tray access bypass
GHSA-6hpj-9xj7-2jxx
Drupal access control bypass vulnerability
GHSA-66mv-q8r2-hj8w
Drupal access bypass vulnerability
GHSA-f4qx-jqfq-7785
Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions
GHSA-3327-jr93-7hq3
Drupal access bypass vulnerability
GHSA-rhx9-3qf7-r3j7
Drupal Remote code execution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-26gr-c7rc-wwqj Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions. | 2% Низкий | около 4 лет назад | ||
GHSA-hqq6-wqq7-jgjq Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL. | 2% Низкий | около 4 лет назад | ||
GHSA-7fh9-933g-885p Drupal Core Remote Code Execution Vulnerability | CVSS3: 9.8 | 100% Критический | около 4 лет назад | |
GHSA-g78h-pf65-46rv Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-7ffh-cjvg-fpr4 Drupal Settings Tray access bypass | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-6hpj-9xj7-2jxx Drupal access control bypass vulnerability | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-66mv-q8r2-hj8w Drupal access bypass vulnerability | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-f4qx-jqfq-7785 Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-3327-jr93-7hq3 Drupal access bypass vulnerability | CVSS3: 8.1 | 1% Низкий | около 4 лет назад | |
GHSA-rhx9-3qf7-r3j7 Drupal Remote code execution | CVSS3: 8.1 | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу