Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

github логотип

GHSA-3gx6-h57h-rm27

больше 3 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-3gw2-26w5-pcm6

больше 3 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

EPSS: Низкий
github логотип

GHSA-3crq-c4rc-qm8q

больше 3 лет назад

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

EPSS: Низкий
github логотип

GHSA-39g6-x4x8-5jcm

9 месяцев назад

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3837-2vcf-c962

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-337j-2h57-4h8m

больше 3 лет назад

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

EPSS: Низкий
github логотип

GHSA-3327-jr93-7hq3

больше 3 лет назад

Drupal access bypass vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qph-q8xw-gv7q

9 месяцев назад

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

EPSS: Низкий
github логотип

GHSA-2p28-5mvp-2j2r

больше 3 лет назад

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2gh8-q6wj-fwpq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

EPSS: Низкий
github логотип

GHSA-2fqf-xc87-725c

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

EPSS: Низкий
github логотип

GHSA-297x-j9pm-xjgg

больше 1 года назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-26gr-c7rc-wwqj

больше 3 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

EPSS: Низкий
github логотип

GHSA-229h-mpm4-83qq

больше 3 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS: Низкий
nvd логотип

CVE-2025-31675

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-31674

9 месяцев назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-31673

9 месяцев назад

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2025-3057

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-13083

около 1 месяца назад

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-13082

около 1 месяца назад

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gx6-h57h-rm27

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
94%
Критический
больше 3 лет назад
github логотип
GHSA-3gw2-26w5-pcm6

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3crq-c4rc-qm8q

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-39g6-x4x8-5jcm

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3837-2vcf-c962

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-337j-2h57-4h8m

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3327-jr93-7hq3

Drupal access bypass vulnerability

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qph-q8xw-gv7q

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

0%
Низкий
9 месяцев назад
github логотип
GHSA-2p28-5mvp-2j2r

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gh8-q6wj-fwpq

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fqf-xc87-725c

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-297x-j9pm-xjgg

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
94%
Критический
больше 1 года назад
github логотип
GHSA-26gr-c7rc-wwqj

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-229h-mpm4-83qq

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2025-31675

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-31674

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-31673

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 4.6
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-3057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-13083

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-13082

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу