Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-3837-2vcf-c962

около 3 лет назад

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-337j-2h57-4h8m

около 3 лет назад

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

EPSS: Низкий
github логотип

GHSA-3327-jr93-7hq3

около 3 лет назад

Drupal access bypass vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qph-q8xw-gv7q

3 месяца назад

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

EPSS: Низкий
github логотип

GHSA-2p28-5mvp-2j2r

около 3 лет назад

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2gh8-q6wj-fwpq

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

EPSS: Низкий
github логотип

GHSA-2fqf-xc87-725c

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

EPSS: Низкий
github логотип

GHSA-297x-j9pm-xjgg

около 1 года назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-26gr-c7rc-wwqj

около 3 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

EPSS: Низкий
github логотип

GHSA-229h-mpm4-83qq

около 3 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS: Низкий
nvd логотип

CVE-2025-31675

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-31674

3 месяца назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-31673

3 месяца назад

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2025-3057

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-55638

6 месяцев назад

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-55638

6 месяцев назад

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-55638

6 месяцев назад

Deserialization of Untrusted Data vulnerability in Drupal Core allows ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-55637

6 месяцев назад

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-55637

6 месяцев назад

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-55637

6 месяцев назад

Deserialization of Untrusted Data vulnerability in Drupal Core allows ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3837-2vcf-c962

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

1%
Низкий
около 3 лет назад
github логотип
GHSA-337j-2h57-4h8m

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3327-jr93-7hq3

Drupal access bypass vulnerability

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2qph-q8xw-gv7q

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

0%
Низкий
3 месяца назад
github логотип
GHSA-2p28-5mvp-2j2r

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2gh8-q6wj-fwpq

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2fqf-xc87-725c

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

0%
Низкий
около 3 лет назад
github логотип
GHSA-297x-j9pm-xjgg

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
94%
Критический
около 1 года назад
github логотип
GHSA-26gr-c7rc-wwqj

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

2%
Низкий
около 3 лет назад
github логотип
GHSA-229h-mpm4-83qq

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

1%
Низкий
около 3 лет назад
nvd логотип
CVE-2025-31675

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-31674

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-31673

Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 4.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-3057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.

CVSS3: 6.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2024-55638

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
3%
Низкий
6 месяцев назад
nvd логотип
CVE-2024-55638

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
3%
Низкий
6 месяцев назад
debian логотип
CVE-2024-55638

Deserialization of Untrusted Data vulnerability in Drupal Core allows ...

CVSS3: 9.8
3%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2024-55637

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
2%
Низкий
6 месяцев назад
nvd логотип
CVE-2024-55637

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

CVSS3: 9.8
2%
Низкий
6 месяцев назад
debian логотип
CVE-2024-55637

Deserialization of Untrusted Data vulnerability in Drupal Core allows ...

CVSS3: 9.8
2%
Низкий
6 месяцев назад

Уязвимостей на страницу