Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2007-4064

Published Jul 30, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3817

Published Jul 17, 2007

Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" l…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3818

Published Jul 17, 2007

Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3689

Published Jul 11, 2007

The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3690

Published Jul 11, 2007

The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxono…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2159

Published Apr 22, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2160

Published Apr 22, 2007

Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1368

Published Mar 9, 2007

The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-1360

Published Mar 8, 2007

Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' profiles via unspecified URL p…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7109

Published Mar 5, 2007

Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension s…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7110

Published Mar 5, 2007

Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1033

Published Feb 21, 2007

Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0658

Published Feb 1, 2007

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote atta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0626

Published Jan 31, 2007

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and acces…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0507

Published Jan 26, 2007

SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree alb…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0136

Published Jan 9, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0124

Published Jan 9, 2007

Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page c…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6647

Published Dec 20, 2006

Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HT…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6528

Published Dec 14, 2006

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privilege…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6529

Published Dec 14, 2006

The Chatroom Module before 4.7.x.-1.0 for Drupal displays private messages in a chatroom's last messages overview, which allows remote attackers to obtain sensitive information by…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 801-825 of 866 CVEsPage 33 of 35