drupal

509 tracked vulnerabilities.

CVE-2008-3661
Drupal - Session Cookie Secure Flag Not Set
Sep 23, 2008
EPSS 0.02
CVE-2008-3740
Drupal 5.x < 5.10 and 6.x < 6.4 - Cross-Site Scripting
Aug 27, 2008
EPSS 0.00
CVE-2008-3741
Drupal 5.x < 5.10 and 6.x < 6.4 - Authenticated Cross-Site Scripting via File Upload MIME Type
Aug 27, 2008
EPSS 0.00
CVE-2008-3742
Drupal 5.x < 5.10 and 6.x < 6.4 - Authenticated Remote Code Execution via BlogAPI Module File Upload
Aug 27, 2008
EPSS 0.03
CVE-2008-3743
Drupal 6.x < 6.4 - Cross-Site Request Forgery via Cached Forms and AHAH Elements
Aug 27, 2008
EPSS 0.01
CVE-2008-3744
Drupal 5.x < 5.10 and 6.x < 6.4 - Cross-Site Request Forgery
Aug 27, 2008
EPSS 0.00
CVE-2008-3745
Drupal Upload module < 6.4 - Authenticated Unauthorized Node Edit and File Deletion
Aug 27, 2008
EPSS 0.01
CVE-2008-3500
Drupal Suggested Terms module 5.x - Authenticated Cross-Site Scripting via Taxonomy Terms
Aug 06, 2008
EPSS 0.00
CVE-2008-3218
Drupal 6.0-6.2 - Cross-Site Scripting via Taxonomy Term Preview and OpenID Values
Jul 18, 2008
EPSS 0.01
CVE-2008-3219
Drupal 5.x < 5.8 and 6.x < 6.3 - Cross-Site Scripting via Object HTML Tag
Jul 18, 2008
EPSS 0.01
CVE-2008-3220
Drupal 5.x < 5.8 and 6.x < 6.3 - Cross-Site Request Forgery via Translated Strings Deletion
Jul 18, 2008
EPSS 0.00
CVE-2008-3221
Drupal 6.x < 6.3 - Cross-Site Request Forgery via OpenID Identity Deletion
Jul 18, 2008
EPSS 0.00
CVE-2008-3222
Drupal 5.x < 5.9 and 6.x < 6.3 - Session Fixation
Jul 18, 2008
EPSS 0.01
CVE-2008-3223
Drupal 6.x < 6.3 - SQL Injection via Numeric Field Placeholder
Jul 18, 2008
EPSS 0.01
CVE-2008-3091
Drupal Taxonomy Autotagger Module < 5.x-1.8 - Authenticated Cross-Site Scripting
Jul 09, 2008
EPSS 0.00
CVE-2008-3092
Drupal Taxonomy Autotagger Module < 5.x-1.8 - Authenticated SQL Injection
Jul 09, 2008
EPSS 0.00
CVE-2008-3095
Drupal Organic Groups Module 5.x < 5.x-7.3 and 6.x < 6.x-1.0-RC1 - Authenticated Cross-Site Scripting
Jul 09, 2008
EPSS 0.00
CVE-2008-3096
Drupal Outline Designer Module - Privilege Escalation via Authentication Level Change
Jul 09, 2008
EPSS 0.01
CVE-2008-3097
Tinytax Taxonomy Block Module 5.x - Authenticated Cross-Site Scripting via Taxonomy Term
Jul 09, 2008
EPSS 0.00
CVE-2008-2998
Drupal Aggregation Module < 5.x-4.4 - Cross-Site Scripting
Jul 03, 2008
EPSS 0.00
CVE-2008-2999
Drupal Aggregation module 5.x < 5.x-4.4 - SQL Injection
Jul 03, 2008
EPSS 0.00
CVE-2008-3000
Drupal Aggregation Module 5.x - Unauthenticated Access Control Bypass
Jul 03, 2008
EPSS 0.00
CVE-2008-3001
Drupal Aggregation Module 5.x - Remote Code Execution via Crafted Feed File Upload
Jul 03, 2008
EPSS 0.02
CVE-2008-2849
TrailScout module < 5.x-1.4 - Authenticated Cross-Site Scripting
Jun 25, 2008
EPSS 0.00
CVE-2008-2850
Drupal Trailscout Module - SQL Injection
Jun 25, 2008
EPSS 0.00