Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2019-10911

Published May 16, 2019

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privilege…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-10910

Published May 16, 2019

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-10909

Published May 16, 2019

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user i…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-6340

Published Feb 21, 2019

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in…

CVSS 8.1 · High
evidence mentions
13
Buzz score
64.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-6339

Published Jan 22, 2019

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when p…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6923

Published Jan 22, 2019

In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict acce…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6922

Published Jan 22, 2019

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2019-6338

Published Jan 22, 2019

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a se…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6921

Published Jan 15, 2019

In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6924

Published Jan 15, 2019

In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to…

CVSS 7.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6925

Published Jan 15, 2019

In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. Thi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6920

Published Aug 6, 2018

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-14773

Published Aug 3, 2018

An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 throu…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2018-7602

Published Jul 19, 2018

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal sit…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
70.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-9861

Published Apr 19, 2018

Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9205

Published Apr 4, 2018

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-5170

Published Mar 29, 2018

The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7600

Published Mar 29, 2018

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystem…

CVSS 9.8 · Critical
evidence mentions
56
Buzz score
72.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-6932

Published Mar 1, 2018

Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and co…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6931

Published Mar 1, 2018

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6930

Published Mar 1, 2018

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback fo…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6929

Published Mar 1, 2018

A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 866 CVEsPage 5 of 35