drupal

509 tracked vulnerabilities.

CVE-2008-2771
Drupal Node Hierarchy Module - Unauthenticated Node Hierarchy Modification via Access Check Bypass
Jun 18, 2008
EPSS 0.00
CVE-2008-2772
Drupal Magic Tabs Module 5.x - Remote Code Execution via URL Argument Injection
Jun 18, 2008
EPSS 0.01
CVE-2008-2773
Taxonomy Image Module 5.x-1.3 and 6.x-1.3 - Cross-Site Scripting
Jun 18, 2008
EPSS 0.00
CVE-2008-1978
Drupal Ubercart Module < 5-1.0 - Authenticated Cross-Site Scripting via Node Titles
Apr 27, 2008
EPSS 0.00
CVE-2008-1980
Drupal E-Publish <5-1.1 and <6-1.0 - Cross-Site Scripting
Apr 27, 2008
EPSS 0.00
CVE-2008-1916
Drupal Ubercart Module < 5.x-1.0-rc1 - Cross-Site Scripting via Address and Order Information Fields
Apr 23, 2008
EPSS 0.00
CVE-2008-1794
Drupal Webform <5.x-1.10, <5.x-2.0-beta3, <6.x-1.0-beta3 - XSS
Apr 15, 2008
EPSS 0.00
CVE-2008-1729
Drupal 6.0-6.1 - Unauthenticated Profile Editing and Information Disclosure via Menu System
Apr 11, 2008
EPSS 0.01
CVE-2008-1428
Drupal Ubercart Module < 5-1.0 - Cross-Site Scripting via Product Text Attribute
Mar 20, 2008
EPSS 0.00
CVE-2008-1133
Drupal 6.0 - Cross-Site Scripting via checkPlain Function
Mar 04, 2008
EPSS 0.00
CVE-2008-1131
Drupal 6.0 - Authenticated Cross-Site Scripting via Content Edit Form Titles
Mar 04, 2008
EPSS 0.00
CVE-2008-0823
Drupal Header Image Module - Unauthenticated Administration Page Access
Feb 19, 2008
EPSS 0.01
CVE-2008-0568
Drupal Secure Site <4.7.x-1.0, <5.x-1.0 - Privilege Escalation
Feb 05, 2008
EPSS 0.01
CVE-2008-0569
Comment Upload Module for Drupal - Arbitrary File Upload and Possible Remote Code Execution
Feb 05, 2008
EPSS 0.01
CVE-2008-0570
Drupal OpenID 5.x-1.0 - Improper Input Validation in claimed_id Verification
Feb 05, 2008
EPSS 0.00
CVE-2008-0571
Userpoints Module 4.7.x-2.3 5.x-2.16 5.x-3.3 - Cross-Site Request Forgery
Feb 05, 2008
EPSS 0.00
CVE-2008-0576
Drupal Project Issue Tracking Module XSS (5.x-2.x-dev, 5.x-1.x <= 1.2, 4.7.x-2.x <= 2.6, 4.7.x-1.x <= 1.6)
Feb 05, 2008
EPSS 0.00
CVE-2008-0577
Drupal Project Issue Tracking Module File Upload/Execution Vulnerability
Feb 05, 2008
EPSS 0.00
CVE-2008-0462
Drupal Archive Module < 5.x-1.8 - Cross-Site Scripting
Jan 25, 2008
EPSS 0.00
CVE-2008-0463
Drupal Workflow < 4.7.x-1.1 - Cross-Site Scripting via Node Properties
Jan 25, 2008
EPSS 0.00
CVE-2008-0264
Drupal Meta Tags Module < 5.x-1.6 - Authenticated Remote Code Execution
Jan 15, 2008
EPSS 0.01
CVE-2008-0271
BUEditor < 4.7.x-1.0 - Cross-Site Request Forgery via Editor Deletion Form
Jan 15, 2008
EPSS 0.00
CVE-2008-0272
Drupal 4.7.x-4.7.10 and 5.x-5.5 - Cross-Site Request Forgery in Aggregator Module
Jan 15, 2008
EPSS 0.00
CVE-2008-0273
Drupal 4.7.x < 4.7.11 and 5.x < 5.6 - Cross-Site Scripting via Invalid UTF-8 Byte Sequences
Jan 15, 2008
EPSS 0.01
CVE-2008-0274
Drupal 4.7.x and 5.x - Cross-Site Scripting via Theme Template Files
Jan 15, 2008
EPSS 0.01