Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2008-4153

Published Sep 24, 2008

The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4152

Published Sep 24, 2008

Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary w…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4149

Published Sep 24, 2008

Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4148

Published Sep 24, 2008

SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4147

Published Sep 24, 2008

Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3661

Published Sep 23, 2008

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3740

Published Aug 27, 2008

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3741

Published Aug 27, 2008

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scrip…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3742

Published Aug 27, 2008

Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3743

Published Aug 27, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3744

Published Aug 27, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for r…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3745

Published Aug 27, 2008

The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3500

Published Aug 6, 2008

Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3218

Published Jul 18, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3219

Published Jul 18, 2008

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3220

Published Jul 18, 2008

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3221

Published Jul 18, 2008

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3222

Published Jul 18, 2008

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3223

Published Jul 18, 2008

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placehold…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3091

Published Jul 9, 2008

Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3092

Published Jul 9, 2008

SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arb…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3095

Published Jul 9, 2008

Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, w…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3096

Published Jul 9, 2008

The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, which might allow remote attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3097

Published Jul 9, 2008

Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2998

Published Jul 3, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 726-750 of 866 CVEsPage 30 of 35