Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

ubuntu логотип

CVE-2020-9281

больше 6 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cchx-mfrc-fwqr

больше 6 лет назад

Improper authentication in Symfony

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2715

больше 6 лет назад

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-2714

больше 6 лет назад

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6rmq-x2hv-vxpp

больше 6 лет назад

Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-pgwj-prpq-jpc2

больше 6 лет назад

Symfony Service IDs Allow Injection

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-2726

больше 6 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2726

больше 6 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-2726

больше 6 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL. This issue affects Drupal 7.x only.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g996-q5r8-w7g2

больше 6 лет назад

Symfony Cross-site Scripting (XSS) vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-9281

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVSS3: 6.1
4%
Низкий
больше 6 лет назад
github логотип
GHSA-cchx-mfrc-fwqr

Improper authentication in Symfony

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-2715

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-2714

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
github логотип
GHSA-6rmq-x2hv-vxpp

Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data

CVSS3: 8
2%
Низкий
больше 6 лет назад
github логотип
GHSA-pgwj-prpq-jpc2

Symfony Service IDs Allow Injection

CVSS3: 9.8
6%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL. This issue affects Drupal 7.x only.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
github логотип
GHSA-g996-q5r8-w7g2

Symfony Cross-site Scripting (XSS) vulnerability

CVSS3: 5.4
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться