Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2020-13666

Published May 5, 2021

Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versio…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35191

Published Dec 17, 2020

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affecte…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13671

Published Nov 20, 2020

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type…

CVSS 8.8 · High
evidence mentions
8
Buzz score
60.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-6342

Published May 28, 2020

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not af…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2020-9281

Published Mar 7, 2020

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protec…

CVSS 6.1 · Medium

CVE-2013-4226

Published Feb 18, 2020

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2715

Published Jan 14, 2020

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-2714

Published Jan 14, 2020

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19826

Published Dec 16, 2019

The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP obje…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3373

Published Nov 25, 2019

Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify n…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2079

Published Nov 22, 2019

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2078

Published Nov 21, 2019

Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1637

Published Nov 21, 2019

Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18856

Published Nov 11, 2019

A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2473

Published Nov 7, 2019

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their ses…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2472

Published Nov 7, 2019

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language na…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2250

Published Nov 7, 2019

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11876

Published May 24, 2019

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 866 CVEsPage 4 of 35