Skip to main content

Vendor/product archive

speedtech / storm CVEs

Beta · best-effort

3 CVEs tagged to speedtech / storm0 Critical, 0 High, 1 Medium, 2 Low, 0 Unrated.

CVE-2010-2158

Published Jun 7, 2010

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2123

Published Jun 1, 2010

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4515

Published Dec 31, 2009

The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecifi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1