Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Drupal MEDIUM 5.3
CVE-2024-45440EPSS 9%

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of…

No fix yet
Fix from $1,600 2024-08-29
Drupal HIGH 7.5
CVE-2024-22362

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a…

Mitigation only
Fix from $1,950 2024-01-16
Drupal CRITICAL 9.8
CVE-2019-6342

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Wor…

Mitigation only
Fix from $2,300 2020-05-28
Authenticated User Page Caching MEDIUM 6.5
CVE-2013-4226

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which all…

Mitigation only
Fix from $1,600 2020-02-18
Data MEDIUM 6.1
CVE-2011-2714

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field na…

Mitigation only
Fix from $1,600 2020-01-14
Activity HIGH 8.8
CVE-2012-2079

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

Mitigation only
Fix from $1,950 2019-11-22
Avatar Uploader HIGH 7.5
CVE-2018-9205EPSS 56%

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

No fix yet
Fix from $1,950 2018-04-04
Storage Api CRITICAL 9.8
CVE-2014-5170

The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess…

Mitigation only
Fix from $2,300 2018-03-29
Drupal MEDIUM 6.1
CVE-2015-7943

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABj…

Mitigation only
Fix from $1,600 2017-10-18
Drupal HIGH 8.1
CVE-2017-6381

A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the def…

Mitigation only
Fix from $1,950 2017-03-16
Drupal HIGH 7.5
CVE-2017-6377

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resul…

Mitigation only
Fix from $1,950 2017-03-16
Drupal HIGH 7.5
CVE-2017-6379

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a …

Mitigation only
Fix from $1,950 2017-03-16
Drupal MEDIUM 6.1
CVE-2016-7571

Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors invol…

Mitigation only
Fix from $1,600 2016-10-03
Drupal MEDIUM 5.3
CVE-2016-6212

The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypa…

Mitigation only
Fix from $1,600 2016-09-09
Drupal HIGH 8.8
CVE-2016-6211

The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that …

Mitigation only
Fix from $1,950 2016-09-09
Drupal MEDIUM 5.8
CVE-2015-3232

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and con…

Mitigation only
Fix from $1,600 2015-06-22
Mrbs Module MEDIUM 6.8
CVE-2013-7407

Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified vic…

Mitigation only
Fix from $1,600 2014-10-22
Drupal HIGH 7.5
CVE-2014-1475

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

Mitigation only
Fix from $1,950 2014-01-24
Drupal MEDIUM 6.8
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modif…

Mitigation only
Fix from $1,600 2013-10-28
Drupal MEDIUM 6.8
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hij…

Mitigation only
Fix from $1,600 2013-10-28
Drupal HIGH 7.5
CVE-2012-2306

SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via un…

Mitigation only
Fix from $1,950 2012-07-25
Drupal MEDIUM 5.8
CVE-2012-1589

Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct ph…

Mitigation only
Fix from $1,600 2012-05-18
Drupal MEDIUM 5.0
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an err…

No fix yet
Fix from $1,600 2011-09-23
Everyblog HIGH 7.5
CVE-2008-6134

SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified …

Mitigation only
Fix from $1,950 2009-02-14
Everyblog HIGH 7.5
CVE-2008-6136

Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrat…

No fix yet
Fix from $1,950 2009-02-14
Everyblog HIGH 7.5
CVE-2008-6137

EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.

No fix yet
Fix from $1,950 2009-02-14
Node Clone MEDIUM 6.0
CVE-2008-4633

SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, …

Mitigation only
Fix from $1,600 2008-10-21
Shindig Integrator HIGH 7.5
CVE-2008-4597

Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via u…

Mitigation only
Fix from $1,950 2008-10-17
Shindig Integrator HIGH 7.5
CVE-2008-4598

Unspecified vulnerability in Shindig-Integrator 5.x, a module for Drupal, has unspecified impact and remote attack vectors related to "numerous flaws…

Mitigation only
Fix from $1,950 2008-10-17
Drupal MEDIUM 5.0
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http…

Mitigation only
Fix from $1,600 2008-09-23