Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal HIGH 7.2
CVE-2022-25277

Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenam…

Fix: 9.3.19 / 9.4.3+
Fix from $1,950 2023-04-26
Drupal MEDIUM 6.5
CVE-2022-25278

Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data the…

Fix: 9.3.19 / 9.4.3+
Fix from $1,600 2023-04-26
Drupal MEDIUM 6.1
CVE-2022-25276

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary…

Fix: 9.3.19 / 9.4.3+
Fix from $1,600 2023-04-26
Drupal HIGH 7.5
CVE-2022-25273

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co…

Fix: 9.2.18 / 9.3.12+
Fix from $1,950 2023-04-26
Drupal HIGH 7.5
CVE-2022-25275

In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating…

Fix: 7.91 / 9.3.19+
Fix from $1,950 2023-04-26
Drupal MEDIUM 5.4
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, r…

Fix: 9.3.12+
Fix from $1,600 2023-04-26
Drupal HIGH 7.5
CVE-2022-31042

Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using …

Fix: 6.5.7 / 7.4.4+
Fix from $1,950 2022-06-10
Drupal HIGH 7.5
CVE-2022-31043

Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request usi…

Fix: 6.5.7 / 7.4.4+
Fix from $1,950 2022-06-10
Saml Sp 2.0 Single Sign On HIGH 8.8
CVE-2022-26493

Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An a…

Fix: after 8.x-2.24
Fix from $1,950 2022-06-03
Drupal HIGH 8.1
CVE-2022-29248

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that …

Fix: 6.5.6 / 7.4.3+
Fix from $1,950 2022-05-25
Drupal HIGH 7.5
CVE-2022-24775

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak…

Fix: 1.8.4 / 2.1.1+
Fix from $1,950 2022-03-21
Drupal HIGH 7.5
CVE-2022-24729

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plug…

Fix: 4.18.0 / 9.2.15+
Fix from $1,950 2022-03-16
Drupal MEDIUM 5.4
CVE-2022-24728

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may …

Fix: 4.18.0 / 9.2.15+
Fix from $1,600 2022-03-16
Drupal MEDIUM 6.5
CVE-2022-25270

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" perm…

Fix: 9.2.13 / 9.3.6+
Fix from $1,600 2022-02-17
Drupal HIGH 7.5
CVE-2022-25271

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This co…

Fix: 7.88 / 9.2.13+
Fix from $1,950 2022-02-16
Drupal CRITICAL 9.8
CVE-2020-13675

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which cause…

Fix: 8.9.19 / 9.1.13+
Fix from $2,300 2022-02-11
Drupal HIGH 7.5
CVE-2020-13670

Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file…

Fix: 8.8.10 / 8.9.6+
Fix from $1,950 2022-02-11
Drupal HIGH 7.5
CVE-2020-13677

Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access…

Fix: 8.9.19 / 9.1.13+
Fix from $1,950 2022-02-11
Drupal MEDIUM 6.5
CVE-2020-13674

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to p…

Fix: 8.9.19 / 9.1.13+
Fix from $1,600 2022-02-11
Drupal MEDIUM 6.5
CVE-2020-13676

The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are…

Fix: 8.9.19 / 9.1.13+
Fix from $1,600 2022-02-11
Drupal MEDIUM 6.1
CVE-2020-13668

Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit th…

Fix: 8.8.10 / 8.9.6+
Fix from $1,600 2022-02-11
Drupal MEDIUM 6.1
CVE-2020-13669

Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions pri…

Fix: 8.8.10 / 8.9.6+
Fix from $1,600 2022-02-11
Drupal MEDIUM 6.1
CVE-2020-13672

Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances.…

Fix: 7.80 / 8.9.14+
Fix from $1,600 2022-02-11
Entity Embed MEDIUM 6.1
CVE-2020-13673

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivil…

Patch available
Fix from $1,600 2022-02-11
Drupal MEDIUM 5.4
CVE-2021-41165

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may a…

Fix: 4.17.0 / 8.9.20+
Fix from $1,600 2021-11-17
Drupal MEDIUM 5.4
CVE-2021-41164

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module…

Fix: 4.17.0 / 8.9.20+
Fix from $1,600 2021-11-17
Drupal HIGH 8.8
CVE-2020-13663

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead…

Fix: 7.72 / 8.8.8+
Fix from $1,950 2021-06-11
Drupal MEDIUM 6.1
CVE-2020-13688

Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to ex…

Fix: 8.8.10 / 8.9.6+
Fix from $1,600 2021-06-11
Drupal MEDIUM 5.3
CVE-2020-13667

Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't…

Fix: 8.8.10 / 8.9.6+
Fix from $1,600 2021-05-17
Drupal CRITICAL 9.8
CVE-2020-13665

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under…

Fix: 8.8.8 / 8.9.1+
Fix from $2,300 2021-05-05