drupal
509 tracked vulnerabilities.
CVE-2012-2153
Drupal 7.0-7.13 - Authenticated Unauthorized Node Access via Content Overview Page
Oct 01, 2012
EPSS 0.00
CVE-2012-1591
Drupal 7.x < 7.14 - Unauthenticated Private Image Style Information Disclosure
Oct 01, 2012
EPSS 0.00
CVE-2012-1590
Drupal 7.x < 7.14 - Authenticated Information Disclosure via Forum Overview Page
Oct 01, 2012
EPSS 0.00
CVE-2012-1588
Drupal 7.x < 7.14 - Authenticated Denial of Service via Long Email Address in Text Filtering
Oct 01, 2012
EPSS 0.01
CVE-2012-1646
Drupal FAQ < 6.x-1.13 and 7.x-1.x-rc1 - Authenticated Cross-Site Scripting via Title or Detailed Question Parameters
Sep 25, 2012
EPSS 0.01
CVE-2012-2298
RealName module < 6.x-1.5 for Drupal - Cross-Site Scripting via User Names and Autocomplete Callbacks
Aug 14, 2012
EPSS 0.01
CVE-2012-2306
Drupal Addressbook module 6.x-4.2 - SQL Injection
Jul 25, 2012
EPSS 0.00
CVE-2012-2922
Drupal < 7.14 - Unauthenticated Sensitive Information Exposure via q[] Parameter
May 21, 2012
EPSS 0.00
CVE-2012-2339
Glossary module 6.x-1.x < 6.x-1.8 for Drupal - Cross-Site Scripting via Taxonomy Information
May 21, 2012
EPSS 0.01
CVE-2012-1589
Drupal 7.x < 7.13 - Open Redirect via Form API Destination URL
May 18, 2012
EPSS 0.00
CVE-2011-2715
CRITICAL
Drupal Data 6.x-1.0-alpha14 - SQL Injection via Table or Column Name
Jan 14, 2020
CVSS 9.8
EPSS 0.00
CVE-2011-2714
MEDIUM
Drupal Data 6.x-1.0-alpha14 - Cross-Site Scripting in Table Descriptions
Jan 14, 2020
CVSS 6.1
EPSS 0.00
CVE-2011-3373
MEDIUM
Drupal Views Builk Operations 6.x-1.0-6.x-1.10 - XSS
Nov 25, 2019
CVSS 6.1
EPSS 0.01
CVE-2011-2726
HIGH
Drupal 7.0-7.5 - Unauthenticated File Download via Direct URL Access
Nov 15, 2019
CVSS 7.5
EPSS 0.00
CVE-2011-4560
Petition Node module < 6.x-1.5 - Authenticated Cross-Site Scripting
Nov 28, 2011
EPSS 0.00
CVE-2011-3730
Drupal 7.0 - Exposure of Sensitive Information via Direct PHP File Request
Sep 23, 2011
EPSS 0.01
CVE-2011-2687
Drupal 7.x < 7.3 - Unauthenticated Node Access Bypass via Missing JOIN Clause
Jul 27, 2011
EPSS 0.01
CVE-2010-2473
MEDIUM
Drupal 5.0-5.21 - Unauthenticated Session Persistence via Blocked User Bypass
Nov 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2010-2472
MEDIUM
Drupal 5.0-5.21 - Authenticated Cross-Site Scripting in Locale Module
Nov 07, 2019
CVSS 4.8
EPSS 0.00
CVE-2010-2250
MEDIUM
Drupal 5.0-5.22 - Cross-Site Scripting during Site Installation
Nov 07, 2019
CVSS 6.1
EPSS 0.01
CVE-2010-2471
MEDIUM
Drupal 5.x-6.x - Open Redirect
Nov 06, 2019
CVSS 6.1
EPSS 0.01
CVE-2010-5312
MEDIUM
jQuery UI <1.10.0 - XSS
Nov 24, 2014
CVSS 6.1
EPSS 0.06
CVE-2010-3686
Drupal OpenID Module < 6.18 and 5.x-1.4 - Authentication Bypass via Unsigned OpenID Fields
Sep 29, 2010
EPSS 0.01
CVE-2010-3685
Drupal OpenID Module - Authentication Bypass via OpenID Response Nonce Reuse
Sep 29, 2010
EPSS 0.01
CVE-2010-3091
Drupal <6.18 & <5.x-1.4 - Auth Bypass
Sep 29, 2010
EPSS 0.01
Products
drupal 273
core 91
core-recommended 6
project_issue_tracking_module 6
Drupal core 5
print 5
aggregation_module 4
ai 4
everyblog 4
project 4
ubercart_module 4
Drupal Core 3
OpenID Connect / OAuth client 3
content_construction_kit 3
drupal_project_issue_tracking 3
shindig-integrator 3
File Access Fix (deprecated) 2
activity 2
ajax_checklist 2
artificial_intelligence 2
bibliography_module 2
brilliant_gallery 2
chatroom_module 2
civictheme 2
cookies_consent_management 2
custom_search_module 2
data 2
database_administration_module 2
drupal_easylinks_module 2
google_tag 2
Quick Filters