Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

ubuntu логотип

CVE-2022-24728

больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-24728

больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-24728

больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2021-05771

около 4 лет назад

Уязвимость пакета Archive_Tar библиотеки PHP классов PEAR CMS-системы Drupal, позволяющая нарушителю оказать влияние на целостность, доступность и конфиденциальность данных

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2021-03621

больше 4 лет назад

Уязвимость функции _maliciousFilename класса Archive_Tar библиотеки PHP классов PEAR, позволяющая нарушителю выполнить произвольный PHP-код

CVSS3: 8.8
EPSS: Высокий
fstec логотип

BDU:2021-03618

больше 4 лет назад

Уязвимость класса Archive_Tar библиотеки PHP классов PEAR, позволяющая нарушителю выполнить перезапись защищаемых файлов

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-pvmx-g8h5-cprj

больше 3 лет назад

Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-7h26-63m7-qhf2

больше 3 лет назад

HTML comments vulnerability allowing to execute JavaScript code

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2021-41165

больше 3 лет назад

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2021-41165

больше 3 лет назад

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-41165

больше 3 лет назад

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2021-41164

больше 3 лет назад

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2021-41164

больше 3 лет назад

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2021-41164

больше 3 лет назад

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-vcjf-mgcg-jxjq

около 4 лет назад

CKEditor 4.0 vulnerability in the HTML Data Processor

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7c37-p4gh-wrh2

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

EPSS: Низкий
ubuntu логотип

CVE-2020-9281

больше 5 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-9281

больше 5 лет назад

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2007-5621

почти 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

CVSS2: 3.5
EPSS: Низкий
github логотип

GHSA-j7qv-pgf6-hvh4

почти 4 года назад

XSS in `*Text` options of the Datepicker widget in jquery-ui

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. ...

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-05771

Уязвимость пакета Archive_Tar библиотеки PHP классов PEAR CMS-системы Drupal, позволяющая нарушителю оказать влияние на целостность, доступность и конфиденциальность данных

CVSS3: 7.1
1%
Низкий
около 4 лет назад
fstec логотип
BDU:2021-03621

Уязвимость функции _maliciousFilename класса Archive_Tar библиотеки PHP классов PEAR, позволяющая нарушителю выполнить произвольный PHP-код

CVSS3: 8.8
70%
Высокий
больше 4 лет назад
fstec логотип
BDU:2021-03618

Уязвимость класса Archive_Tar библиотеки PHP классов PEAR, позволяющая нарушителю выполнить перезапись защищаемых файлов

CVSS3: 8.8
93%
Критический
больше 4 лет назад
github логотип
GHSA-pvmx-g8h5-cprj

Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7h26-63m7-qhf2

HTML comments vulnerability allowing to execute JavaScript code

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-41165

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-41165

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-41165

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a ...

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-41164

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-41164

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-41164

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions ...

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-vcjf-mgcg-jxjq

CKEditor 4.0 vulnerability in the HTML Data Processor

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-7c37-p4gh-wrh2

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-9281

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-9281

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2007-5621

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

CVSS2: 3.5
0%
Низкий
почти 18 лет назад
github логотип
GHSA-j7qv-pgf6-hvh4

XSS in `*Text` options of the Datepicker widget in jquery-ui

CVSS3: 6.5
2%
Низкий
почти 4 года назад

Уязвимостей на страницу