Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal HIGH 8.8
CVE-2020-13664

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malic…

Fix: 8.8.8 / 8.9.1+
Fix from $1,950 2021-05-05
Drupal MEDIUM 6.1
CVE-2020-13662

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitra…

Fix: after 7.70
Fix from $1,600 2021-05-05
Drupal MEDIUM 6.1
CVE-2020-13666

Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects:…

Fix: 7.73 / 8.8.10+
Fix from $1,600 2021-05-05
Drupal Docker Images CRITICAL 9.8
CVE-2020-35191

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker…

Fix: after 8.5.10-fpm-alpine
Fix from $2,300 2020-12-17
Drupal HIGH 8.8
CVE-2020-13671 KEV

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and …

Fix: 7.74 / 8.8.11+
Fix from $1,950 2020-11-20
Drupal CRITICAL 9.8
CVE-2019-6342

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Wor…

Mitigation only
Fix from $2,300 2020-05-28
Authenticated User Page Caching MEDIUM 6.5
CVE-2013-4226

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which all…

Mitigation only
Fix from $1,600 2020-02-18
Data CRITICAL 9.8
CVE-2011-2715

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

Patch available
Fix from $2,300 2020-01-14
Data MEDIUM 6.1
CVE-2011-2714

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field na…

Mitigation only
Fix from $1,600 2020-01-14
Views Dynamic Field CRITICAL 9.8
CVE-2019-19826

The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.in…

Fix: after 6.x-1.4
Fix from $2,300 2019-12-16
Views Builk Operations MEDIUM 6.1
CVE-2011-3373

Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tag…

Fix: after 6.x1.10
Fix from $1,600 2019-11-25
Activity HIGH 8.8
CVE-2012-2079

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

Mitigation only
Fix from $1,950 2019-11-22
Drupal HIGH 7.5
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type i…

Fix: 7.5+
Fix from $1,950 2019-11-15
Svg Sanitizer HIGH 7.5
CVE-2019-18856

A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an S…

Fix: after 7.x-1.5
Fix from $1,950 2019-11-11
Drupal MEDIUM 6.5
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was bl…

Fix: 5.22 / 6.16+
Fix from $1,600 2019-11-07
Drupal MEDIUM 6.1
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform…

Fix: 5.22 / 6.16+
Fix from $1,600 2019-11-07
Drupal MEDIUM 6.1
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

Fix: 5.22 / 6.16+
Fix from $1,600 2019-11-06
Drupal MEDIUM 5.4
CVE-2019-6341EPSS 12%

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File mod…

Fix: 7.65 / 8.5.14+
Fix from $1,600 2019-03-26
Drupal HIGH 8.1
CVE-2019-6340 KEVEPSS 92%

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to a…

Fix: 8.5.11 / 8.6.10+
Fix from $1,950 2019-02-21
Drupal CRITICAL 9.8
CVE-2019-6339EPSS 33%

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built…

Fix: 7.62 / 8.5.9+
Fix from $2,300 2019-01-22
Drupal MEDIUM 6.5
CVE-2017-6922

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently a…

Fix: 7.56 / 8.3.4+
Fix from $1,600 2019-01-22
Drupal MEDIUM 6.5
CVE-2017-6923

In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsyste…

Fix: after 8.3.7
Fix from $1,600 2019-01-22
Drupal HIGH 8.0
CVE-2019-6338

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. …

Fix: 7.62 / 8.5.9+
Fix from $1,950 2019-01-22
Drupal MEDIUM 5.9
CVE-2017-6921

In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if…

Fix: 8.3.4+
Fix from $1,600 2019-01-15
Drupal HIGH 7.4
CVE-2017-6924

In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the us…

Fix: 8.3.7+
Fix from $1,950 2019-01-15
Drupal CRITICAL 9.8
CVE-2017-6925

In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, u…

Fix: 8.3.7+
Fix from $2,300 2019-01-15
Drupal CRITICAL 9.8
CVE-2017-6920EPSS 20%

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely dur…

Fix: 8.3.4+
Fix from $2,300 2018-08-06
Drupal CRITICAL 9.8
CVE-2018-7602 KEVEPSS 99%

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple …

Fix: 7.59 / 8.4.8+
Fix from $2,300 2018-07-19
Drupal MEDIUM 6.1
CVE-2018-9861

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), a…

Fix: 4.9.2 / 8.4.7+
Fix from $1,600 2018-04-19
Avatar Uploader HIGH 7.5
CVE-2018-9205EPSS 56%

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

No fix yet
Fix from $1,950 2018-04-04