drupal

509 tracked vulnerabilities.

CVE-2012-2153
Drupal 7.0-7.13 - Authenticated Unauthorized Node Access via Content Overview Page
Oct 01, 2012
EPSS 0.00
CVE-2012-1591
Drupal 7.x < 7.14 - Unauthenticated Private Image Style Information Disclosure
Oct 01, 2012
EPSS 0.00
CVE-2012-1590
Drupal 7.x < 7.14 - Authenticated Information Disclosure via Forum Overview Page
Oct 01, 2012
EPSS 0.00
CVE-2012-1588
Drupal 7.x < 7.14 - Authenticated Denial of Service via Long Email Address in Text Filtering
Oct 01, 2012
EPSS 0.01
CVE-2012-1646
Drupal FAQ < 6.x-1.13 and 7.x-1.x-rc1 - Authenticated Cross-Site Scripting via Title or Detailed Question Parameters
Sep 25, 2012
EPSS 0.01
CVE-2012-2298
RealName module < 6.x-1.5 for Drupal - Cross-Site Scripting via User Names and Autocomplete Callbacks
Aug 14, 2012
EPSS 0.01
CVE-2012-2306
Drupal Addressbook module 6.x-4.2 - SQL Injection
Jul 25, 2012
EPSS 0.00
CVE-2012-2922
Drupal < 7.14 - Unauthenticated Sensitive Information Exposure via q[] Parameter
May 21, 2012
EPSS 0.00
CVE-2012-2339
Glossary module 6.x-1.x < 6.x-1.8 for Drupal - Cross-Site Scripting via Taxonomy Information
May 21, 2012
EPSS 0.01
CVE-2012-1589
Drupal 7.x < 7.13 - Open Redirect via Form API Destination URL
May 18, 2012
EPSS 0.00
CVE-2011-2715 CRITICAL
Drupal Data 6.x-1.0-alpha14 - SQL Injection via Table or Column Name
Jan 14, 2020
CVSS 9.8
EPSS 0.00
CVE-2011-2714 MEDIUM
Drupal Data 6.x-1.0-alpha14 - Cross-Site Scripting in Table Descriptions
Jan 14, 2020
CVSS 6.1
EPSS 0.00
CVE-2011-3373 MEDIUM
Drupal Views Builk Operations 6.x-1.0-6.x-1.10 - XSS
Nov 25, 2019
CVSS 6.1
EPSS 0.01
CVE-2011-2726 HIGH
Drupal 7.0-7.5 - Unauthenticated File Download via Direct URL Access
Nov 15, 2019
CVSS 7.5
EPSS 0.00
CVE-2011-4560
Petition Node module < 6.x-1.5 - Authenticated Cross-Site Scripting
Nov 28, 2011
EPSS 0.00
CVE-2011-3730
Drupal 7.0 - Exposure of Sensitive Information via Direct PHP File Request
Sep 23, 2011
EPSS 0.01
CVE-2011-2687
Drupal 7.x < 7.3 - Unauthenticated Node Access Bypass via Missing JOIN Clause
Jul 27, 2011
EPSS 0.01
CVE-2010-2473 MEDIUM
Drupal 5.0-5.21 - Unauthenticated Session Persistence via Blocked User Bypass
Nov 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2010-2472 MEDIUM
Drupal 5.0-5.21 - Authenticated Cross-Site Scripting in Locale Module
Nov 07, 2019
CVSS 4.8
EPSS 0.00
CVE-2010-2250 MEDIUM
Drupal 5.0-5.22 - Cross-Site Scripting during Site Installation
Nov 07, 2019
CVSS 6.1
EPSS 0.01
CVE-2010-2471 MEDIUM
Drupal 5.x-6.x - Open Redirect
Nov 06, 2019
CVSS 6.1
EPSS 0.01
CVE-2010-5312 MEDIUM
jQuery UI <1.10.0 - XSS
Nov 24, 2014
CVSS 6.1
EPSS 0.06
CVE-2010-3686
Drupal OpenID Module < 6.18 and 5.x-1.4 - Authentication Bypass via Unsigned OpenID Fields
Sep 29, 2010
EPSS 0.01
CVE-2010-3685
Drupal OpenID Module - Authentication Bypass via OpenID Response Nonce Reuse
Sep 29, 2010
EPSS 0.01
CVE-2010-3091
Drupal <6.18 & <5.x-1.4 - Auth Bypass
Sep 29, 2010
EPSS 0.01