Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

nvd логотип

CVE-2020-13688

больше 4 лет назад

Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-13688

больше 4 лет назад

Cross-site scripting vulnerability in l Drupal Core allows an attacker ...

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2022-06302

больше 4 лет назад

Уязвимость CMS-системы Drupal, связанная с недостаточной проверкой подлинности выполняемых запросов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-33829

больше 4 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVSS3: 6.1
EPSS: Средний
debian логотип

CVE-2021-33829

больше 4 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor ...

CVSS3: 6.1
EPSS: Средний
ubuntu логотип

CVE-2021-33829

больше 4 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVSS3: 6.1
EPSS: Средний
rocky логотип

RLSA-2021:1846

больше 4 лет назад

Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update

EPSS: Средний
nvd логотип

CVE-2020-13667

больше 4 лет назад

Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be able to see content before the site owner intends people to see the content. This vulnerability is mitigated by the fact that sites are only vulnerable if they have installed the experimental Workspaces module. This issue affects Drupal Core8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vcjf-mgcg-jxjq

почти 5 лет назад

CKEditor 4.0 vulnerability in the HTML Data Processor

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-13665

почти 5 лет назад

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-13688

Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-13688

Cross-site scripting vulnerability in l Drupal Core allows an attacker ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-06302

Уязвимость CMS-системы Drupal, связанная с недостаточной проверкой подлинности выполняемых запросов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-33829

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVSS3: 6.1
48%
Средний
больше 4 лет назад
debian логотип
CVE-2021-33829

A cross-site scripting (XSS) vulnerability in the HTML Data Processor ...

CVSS3: 6.1
48%
Средний
больше 4 лет назад
ubuntu логотип
CVE-2021-33829

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVSS3: 6.1
48%
Средний
больше 4 лет назад
rocky логотип
RLSA-2021:1846

Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update

32%
Средний
больше 4 лет назад
nvd логотип
CVE-2020-13667

Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be able to see content before the site owner intends people to see the content. This vulnerability is mitigated by the fact that sites are only vulnerable if they have installed the experimental Workspaces module. This issue affects Drupal Core8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-vcjf-mgcg-jxjq

CKEditor 4.0 vulnerability in the HTML Data Processor

CVSS3: 6.1
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-13665

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.

CVSS3: 9.8
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться