drupal

509 tracked vulnerabilities.

CVE-2008-6160
Semantically-Interconnected Online Communities < 5.x_1.0 - Information Disclosure
Feb 18, 2009
EPSS 0.00
CVE-2008-6137
EveryBlog 5.x and 6.x - Access Restriction Bypass
Feb 14, 2009
EPSS 0.00
CVE-2008-6136
EveryBlog <6.x - Privilege Escalation
Feb 14, 2009
EPSS 0.01
CVE-2008-6135
EveryBlog 5.x and 6.x - Cross-Site Scripting
Feb 14, 2009
EPSS 0.00
CVE-2008-6134
EveryBlog 5.x and 6.x - SQL Injection
Feb 14, 2009
EPSS 0.01
CVE-2008-6020
Drupal 6.x < 6.x-2.2 - SQL Injection
Feb 02, 2009
EPSS 0.01
CVE-2008-5999
Ajax Checklist module <5.x-1.1 - XSS
Jan 28, 2009
EPSS 0.00
CVE-2008-5998
Drupal Ajax Checklist <5.x-1.1 - SQL Injection
Jan 28, 2009
EPSS 0.00
CVE-2008-4793
Drupal 5.x < 5.11 - Node Validation Bypass via Contributed Modules
Oct 29, 2008
EPSS 0.00
CVE-2008-4792
Drupal 5.x < 5.11 and 6.x < 6.5 - Authenticated Access Bypass via BlogAPI Module
Oct 29, 2008
EPSS 0.00
CVE-2008-4791
Drupal 5.x < 5.11 and 6.x < 6.5 - Authenticated Login Access Bypass
Oct 29, 2008
EPSS 0.01
CVE-2008-4790
Drupal < 5.11 - Authenticated Unauthorized File Access
Oct 29, 2008
EPSS 0.00
CVE-2008-4789
Drupal < 6.5 - Authenticated File Upload Bypass via Validation Logic Error
Oct 29, 2008
EPSS 0.00
CVE-2008-4710
Drupal Stock Module < 6.x-1.0 - Cross-Site Scripting
Oct 23, 2008
EPSS 0.00
CVE-2008-4633
Drupal Node Clone - Authenticated SQL Injection via Previously Cast Vote
Oct 21, 2008
EPSS 0.00
CVE-2008-4598
Shindig-Integrator 5.x - Unspecified Remote Vulnerability
Oct 17, 2008
EPSS 0.00
CVE-2008-4597
Shindig-Integrator 5.x - Privilege Escalation
Oct 17, 2008
EPSS 0.01
CVE-2008-4596
Shindig-Integrator 5.x - Authenticated Cross-Site Scripting
Oct 17, 2008
EPSS 0.00
CVE-2008-4531
Brilliant Gallery < 5.x-4.2 - SQL Injection
Oct 09, 2008
EPSS 0.00
CVE-2008-4530
Brilliant Gallery < 5.x-4.2 - Authenticated Cross-Site Scripting
Oct 09, 2008
EPSS 0.00
CVE-2008-4153
Drupal Talk < 5.x-1.3 and 6.x < 6.x-1.5 - Unauthenticated Sensitive Information Exposure via Comment Display
Sep 24, 2008
EPSS 0.00
CVE-2008-4152
Drupal Talk < 5.x-1.3 and 6.x < 6.x-1.5 - Authenticated Cross-Site Scripting via Node Title
Sep 24, 2008
EPSS 0.00
CVE-2008-4149
Drupal Link to Us < 5.x-1.0 - Authenticated Cross-Site Scripting via Link Page Header Field
Sep 24, 2008
EPSS 0.00
CVE-2008-4148
Drupal Mailhandler < 5.x-1.3 - SQL Injection
Sep 24, 2008
EPSS 0.00
CVE-2008-4147
Drupal Mailsave < 5.x-3.3 and 6.x < 6.x-1.3 - Cross-Site Scripting via Email Attachment Content-Type
Sep 24, 2008
EPSS 0.00