Package impact

php Packagist / drupal/drupal

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-9452 medium 6.5 6.5 10y ago Drupal Denial of service via transliterate mechanism
CVE-2016-3168 medium 6.4 6.4 10y ago Drupal Reflected file download vulnerability
CVE-2016-7571 medium 6.1 6.1 10y ago Drupal Cross-site scripting (XSS) vulnerability
CVE-2016-3166 medium 5.9 5.9 10y ago Drupal CRLF injection vulnerability in the drupal_set_header function
CVE-2013-6389 medium 5.8 13y ago Drupal has open redirect vulnerability in the Overlay module
CVE-2012-1589 medium 5.8 14y ago Drupal Open Redirect
CVE-2016-6212 medium 5.3 5.3 10y ago Drupal Views can allow unauthorized users to see Statistics information
CVE-2016-3170 medium 5.3 5.3 10y ago Drupal sensitive information disclosure
CVE-2016-9449 medium 4.3 4.3 10y ago Drupal sensitive information disclosure
CVE-2016-7572 medium 4.3 4.3 10y ago Drupal Unprivileged access to config export
CVE-2016-7570 medium 4.3 4.3 10y ago Drupal Users without "Administer comments" can set comment visibility on nodes they can edit
CVE-2012-2153 medium 4.0 14y ago Drupal improper access restrictions
CVE-2019-6340 unknown 2.5 7y ago In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2020-13671 unknown 1.5 6y ago Improper sanitization in the extension file names is present in Drupal core.
CVE-2019-10909 unknown 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. Th…