Search

Found 441 results in 102ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-9082 critical 9.8 10.0 KEVEXP drupal 14d ago Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-6367 medium 6.1 6.1 drupal 15d ago Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross s…
CVE-2026-6366 medium 6.6 6.6 drupal 15d ago Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a …
CVE-2026-6365 medium 6.1 6.1 drupal 15d ago Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which which can lead to a cross-site scripting (XSS) vulnerability.
CVE-2010-5312 medium 6.1 6.1 FIX debian debianfedora fedora jqueryuinetappapache 9y ago Cross-site Scripting in jquery-ui
CVE-2015-7943 medium 6.1 6.1 drupaljquery_update_projectlabjs_project 9y ago Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote atta…
CVE-2015-7880 medium 4.3 4.3 drupal 9y ago The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and …
CVE-2015-2750 medium 6.1 6.1 debian debian drupal 9y ago Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi…
CVE-2015-2749 medium 6.1 6.1 debian debian drupal 9y ago Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination pa…
CVE-2017-6919 high 7.5 7.5 drupal 9y ago Drupal access control bypass vulnerability
CVE-2017-6381 high 8.1 8.1 drupal 9y ago Drupal Remote code execution
CVE-2017-6379 high 7.5 7.5 drupal 9y ago Drupal Cross-Site Request Forgery (CSRF)
CVE-2017-6377 high 7.5 7.5 drupal 9y ago Drupal editor module incorrectly checks access to inline private files
CVE-2016-9452 medium 6.5 6.5 FIX arch arch drupal 10y ago Drupal Denial of service via transliterate mechanism
CVE-2016-9451 medium 6.8 6.8 FIX arch arch drupal 10y ago Drupal Open Redirect
CVE-2016-9450 high 7.5 7.5 FIX arch arch drupal 10y ago Drupal Incorrect cache context on password reset page
CVE-2016-9449 medium 4.3 4.3 FIX arch arch drupal 10y ago Drupal sensitive information disclosure
CVE-2016-7572 medium 4.3 4.3 drupal 10y ago Drupal Unprivileged access to config export
CVE-2016-7571 medium 6.1 6.1 drupal 10y ago Drupal Cross-site scripting (XSS) vulnerability
CVE-2016-7570 medium 4.3 4.3 drupal 10y ago Drupal Users without "Administer comments" can set comment visibility on nodes they can edit
CVE-2016-6212 medium 5.3 5.3 drupal 10y ago Drupal Views can allow unauthorized users to see Statistics information
CVE-2016-6211 high 8.8 8.8 debian debian drupal 10y ago Drupal Saving user accounts can sometimes grant the user all roles
CVE-2016-5385 high 8.1 8.1 slesfedora fedorasuse suse oraclehpphp 10y ago HTTP Proxy header vulnerability
CVE-2016-3171 high 8.1 8.1 debian debian phpdrupal 10y ago Drupal arbitrary code execution
CVE-2016-3170 medium 5.3 5.3 debian debian drupal 10y ago Drupal sensitive information disclosure
CVE-2016-3169 high 8.1 8.1 debian debian drupal 10y ago Drupal saving user accounts can sometimes grant the user all roles
CVE-2016-3168 medium 6.4 6.4 debian debian drupal 10y ago Drupal Reflected file download vulnerability
CVE-2016-3167 high 7.4 7.4 debian debian phpdrupal 10y ago Drupal Open redirect vulnerability in the drupal_goto function
CVE-2016-3166 medium 5.9 5.9 debian debian drupal 10y ago Drupal CRLF injection vulnerability in the drupal_set_header function
CVE-2016-3165 high 7.5 7.5 drupal 10y ago Drupal Form API ignores access restrictions on submit buttons
CVE-2016-3164 high 7.4 7.4 debian debian drupal 10y ago Drupal Open Redirect
CVE-2016-3163 high 7.5 7.5 debian debian drupal 10y ago Drupal Brute force amplification attacks via XML-RPC
CVE-2016-3162 high 8.1 8.1 debian debian drupal 10y ago Drupal File upload access bypass and denial of service
CVE-2015-8095 medium 5.0 monster_menus_projectdrupal 11y ago The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an …
CVE-2015-6665 medium 4.3 fedora fedora drupalchaos_tool_suite_project 11y ago Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script …
CVE-2015-6661 medium 5.0 drupal 11y ago Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu.
CVE-2015-6660 medium 6.8 drupal 11y ago The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's acc…
CVE-2015-6659 high 7.5 drupal 11y ago SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.
CVE-2015-6658 medium 4.3 drupal 11y ago Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, rel…
CVE-2015-3234 medium 4.3 debian debian drupal 11y ago The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by t…
CVE-2015-3233 medium 5.8 drupal 11y ago Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2015-3232 medium 5.8 debian debian drupal 11y ago Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination…
CVE-2015-3231 medium 4.0 debian debian drupal 11y ago The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
CVE-2015-2559 low 3.5 debian debian drupal 11y ago Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a craf…
CVE-2014-9016 medium 6.0 EXP debian debian drupalsecure_password_hashes_project 12y ago The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and m…
CVE-2014-9015 medium 6.8 debian debian drupal 12y ago Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS session…
CVE-2014-8734 low 3.5 drupal 12y ago The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified ve…
CVE-2013-7407 medium 6.8 drupal 12y ago Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2014-8296 medium 4.3 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-3704 high 8.5 EXP debian debian drupal 12y ago The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection att…
CVE-2014-8765 medium 4.3 drupal 12y ago Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script …
CVE-2014-8748 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission…
CVE-2014-8747 medium 4.3 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content c…
CVE-2014-8746 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject a…
CVE-2014-8745 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" pe…
CVE-2014-8744 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrar…
CVE-2014-8743 low 3.5 drupal 12y ago Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or…
CVE-2014-8079 medium 4.0 drupal 12y ago Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script o…
CVE-2014-8078 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remot…
CVE-2014-8077 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission …
CVE-2014-8076 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web scr…
CVE-2014-8075 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a n…
CVE-2014-7980 low 3.5 drupal 12y ago Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer the…
CVE-2014-7979 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web sc…
CVE-2014-7978 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web s…
CVE-2014-7870 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom searc…
CVE-2014-7869 low 3.5 drupal 12y ago Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer context…
CVE-2014-5267 medium 6.8 drupal 12y ago modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
CVE-2014-5266 medium 6.0 EXPFIX debian debian wordpressdrupal 12y ago The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote atta…
CVE-2014-5265 medium 5.0 FIX debian debian drupalwordpress 12y ago The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion,…
CVE-2014-5022 medium 4.3 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled t…
CVE-2014-5021 low 2.1 drupal 12y ago Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject a…
CVE-2014-5020 medium 4.9 drupal 12y ago The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read …
CVE-2014-5019 medium 5.0 drupal 12y ago The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration fil…
CVE-2013-4178 medium 5.0 google_authenticator_login_projectdrupal 12y ago The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password …
CVE-2013-4177 medium 5.0 google_authenticator_login_projectdrupal 12y ago The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-…
CVE-2013-4380 low 2.1 mediafrontdrupal 12y ago Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "adm…
CVE-2013-4498 low 2.1 florian_weberdrupal 12y ago The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes t…
CVE-2013-4504 low 2.6 monster_menus_projectdrupal 12y ago The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.
CVE-2013-4502 medium 4.0 nathan_haugdrupal 12y ago The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by …
CVE-2013-7302 medium 6.8 ubercartdrupal 12y ago Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote at…
CVE-2014-2983 medium 5.0 debian debian drupal 12y ago Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input informati…
CVE-2013-1946 medium 4.3 restful_web_services_projectdrupal 12y ago The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows …
CVE-2013-4383 low 2.1 dennis_brueckedrupal 13y ago Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject…
CVE-2014-1611 medium 4.3 anonymous_posting_projectdrupal 13y ago Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.
CVE-2014-1607 medium 4.3 drupal 13y ago Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: thi…
CVE-2014-1476 medium 4.0 drupal 13y ago The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to ob…
CVE-2014-1475 high 7.5 drupal 13y ago The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.
CVE-2013-0244 low 2.6 drupal 13y ago Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inj…
CVE-2013-6388 medium 4.3 drupal 13y ago Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.
CVE-2013-6387 low 2.1 drupal 13y ago Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the descri…
CVE-2013-7067 medium 5.8 mike_stefanellodrupal 13y ago The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows remote attackers to bypass intended access restrictio…
CVE-2013-6389 medium 5.8 drupal 13y ago Drupal has open redirect vulnerability in the Overlay module
CVE-2013-6386 medium 6.8 drupal 13y ago Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass in…
CVE-2013-6385 medium 5.1 drupal 13y ago The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote att…
CVE-2013-4446 medium 6.8 steven_jonesdrupal 13y ago The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support t…
CVE-2013-4445 medium 4.9 steven_jonesdrupal 13y ago The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for …
CVE-2012-0827 low 3.5 drupal 13y ago The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields vi…
CVE-2012-0826 medium 6.8 drupal 13y ago Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for …
CVE-2012-0825 medium 6.8 drupal 13y ago Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without det…