Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2008-2999

Published Jul 3, 2008

Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3000

Published Jul 3, 2008

The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intend…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3001

Published Jul 3, 2008

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed tha…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2849

Published Jun 25, 2008

Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrar…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2850

Published Jun 25, 2008

SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to im…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2771

Published Jun 18, 2008

The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2772

Published Jun 18, 2008

The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2773

Published Jun 18, 2008

Cross-site scripting (XSS) vulnerability in the Taxonomy Image module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2629

Published Jun 10, 2008

SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1978

Published Apr 27, 2008

Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before 5.x-1.0 rc3 module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via node…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1980

Published Apr 27, 2008

Cross-site scripting (XSS) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1916

Published Apr 23, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1792

Published Apr 15, 2008

Cross-site scripting (XSS) vulnerability in the insertion filter in the Flickr Drupal module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-alpha allows remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1794

Published Apr 15, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Webform Drupal module 5.x before 5.x-1.10, 5.x-2.x before 5.x-2.0-beta3, and 6.x before 6.x-1.0-beta3 allow remote attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1729

Published Apr 11, 2008

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive informatio…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1731

Published Apr 11, 2008

The Simple Access module for Drupal 5.x through 5.x-1.2-2 does not properly handle the privacy information for nodes, which might allow remote attackers to bypass intended access…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1428

Published Mar 20, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-beta7 module for Drupal allow remote attackers to inject arbitrary web script or HTML via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1133

Published Mar 4, 2008

The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1131

Published Mar 4, 2008

Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0823

Published Feb 19, 2008

Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0568

Published Feb 5, 2008

Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0569

Published Feb 5, 2008

The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass up…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0570

Published Feb 5, 2008

The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0571

Published Feb 5, 2008

The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0576

Published Feb 5, 2008

Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 751-775 of 866 CVEsPage 31 of 35