← Back

Entity Api

entity_api

Vendor: Entity Api Project • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Entity Api Project
Fedoraproject
2Entity Api
Fedora
Nov 21, 2024
Apr 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
2Entity Api Project
Fedoraproject
2Entity Api
Fedora
Nov 21, 2024
Apr 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
2Entity Api Project
Fedoraproject
2Entity Api
Fedora
Nov 21, 2024
Apr 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via u...Show more
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.Show less
1Entity Api Project
1Entity Api
May 6, 2026
Mar 3, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.
1Entity Api Project
1Entity Api
May 6, 2026
Jul 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NO...Show more
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations.Show less
1Entity Api Project
1Entity Api
May 6, 2026
Jul 19, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was...Show more
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to different researcher organizations. CVE-2013-7391 was assigned for the View vector.Show less