Drupal
drupal
443 CVEs • 143 products
Products (143)
Click to collapseToggle
Products (143)
Click to collapse
CVEs (443)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Drupal Sensiolabs2Drupal SymfonyJun 17, 2026 May 16, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration an...Show more |
2Drupal Sensiolabs2Drupal SymfonyJun 17, 2026 May 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is relate...Show more |
2Drupal Sensiolabs2Drupal SymfonyJun 17, 2026 May 16, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symf...Show more |
5Debian DrupalFedoraproject+2 more5Debian Linux DrupalFedora+2 moreJun 17, 2026 May 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as de...Show more |
11Backdropcms DebianDrupal+8 more105Agile Product Lifecycle Management For Process Application ExpressApplication Service Level Management+102 moreJun 17, 2026 Apr 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more |
3Debian DrupalFedoraproject3Debian Linux DrupalFedoraJun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger...Show more |
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by t...Show more |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jan 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted...Show more |
In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views con...Show more |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Jan 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous...Show more |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jan 22, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal c...Show more |
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file...Show more |
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only...Show more |
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use o...Show more |
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations. |
3Debian DrupalSensiolabs3Debian Linux DrupalSymfonyNov 21, 2024 Aug 3, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (l...Show more |
2Debian Drupal2Debian Linux DrupalJun 17, 2026 Jul 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being c...Show more |
2Ckeditor Drupal2Drupal Enhanced ImageJun 17, 2026 Apr 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other produc...Show more |
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. |
The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003. |