Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 029
GHSA-73q4-j324-2qcc
Incorrect authorization in Drupal core
CVE-2022-25270
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
CVE-2022-25271
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
CVE-2022-25271
Drupal core's form API has a vulnerability where certain contributed o ...
CVE-2022-25271
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
BDU:2022-01067
Уязвимость модуля Quick Edit системы управления содержимым Drupal, позволяющая нарушителю получить доступ к конфиденциальной информации
BDU:2022-01066
Уязвимость системы управления содержимым Drupal, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю записать/перезаписать произвольные данные
GHSA-v8wr-r69p-mmwx
Unrestricted Upload of File with Dangerous Type in Drupal core
GHSA-c533-c843-67h8
Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor
GHSA-3m36-mjwj-352c
Drupal core Cross-site Scripting (XSS) vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-73q4-j324-2qcc Incorrect authorization in Drupal core | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-25270 The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-25271 Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-25271 Drupal core's form API has a vulnerability where certain contributed o ... | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-25271 Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
BDU:2022-01067 Уязвимость модуля Quick Edit системы управления содержимым Drupal, позволяющая нарушителю получить доступ к конфиденциальной информации | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
BDU:2022-01066 Уязвимость системы управления содержимым Drupal, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю записать/перезаписать произвольные данные | CVSS3: 7.4 | 1% Низкий | больше 4 лет назад | |
GHSA-v8wr-r69p-mmwx Unrestricted Upload of File with Dangerous Type in Drupal core | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-c533-c843-67h8 Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3m36-mjwj-352c Drupal core Cross-site Scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу