CVEs (279)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leadi...Show more |
Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Dru...Show more |
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on...Show more |
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70...Show more |
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions prior to 7.73; 8.8.x versions prior to...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Jan 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. |
2Drupal Fedoraproject2Drupal FedoraJun 17, 2026 Nov 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting co...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed. |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4. |
8Debian DrupalFedoraproject+5 more70Agile Product Lifecycle Management For Process Agile Product Supplier Collaboration For ProcessApplication Testing Suite+67 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted co...Show more |
7Debian DrupalFedoraproject+4 more52Active Iq Unified Manager Application ExpressApplication Testing Suite+49 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(),...Show more |
4Ckeditor DrupalFedoraproject+1 more11Agile Plm Application ExpressBanking Enterprise Default Management+8 moreJun 17, 2026 Mar 7, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected synt...Show more |
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. |
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display. |
4Debian DrupalFedoraproject+1 more4Debian Linux DrupalEnterprise Linux+1 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields...Show more |
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blo...Show more |
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacke...Show more |
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Drupal versions 5.x and 6.x has open redirection |