Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

ubuntu логотип

CVE-2022-24775

больше 4 лет назад

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4fc4-4p5g-6w89

больше 4 лет назад

Cross-site Scripting in CKEditor4

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-24729

больше 4 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-24729

больше 4 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-24729

больше 4 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-24728

больше 4 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-24728

больше 4 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2022-24728

больше 4 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2022-07065

больше 4 лет назад

Уязвимость плагина dialog WYSIWYG-редактора CKEditor, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fmfv-x8mp-5767

больше 4 лет назад

Improper input validation in Drupal core

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2022-24775

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4fc4-4p5g-6w89

Cross-site Scripting in CKEditor4

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-24729

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-24729

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-24729

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-07065

Уязвимость плагина dialog WYSIWYG-редактора CKEditor, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-fmfv-x8mp-5767

Improper input validation in Drupal core

CVSS3: 7.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться