← Back

Drupal

drupal

443 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Drupal
drupal
Print
print
Project
project
Everyblog
everyblog
Imce Module
imce_module
Talk
talk
Views
views
Activity
activity
Data
data
Job Search
job_search
Recipe Module
recipe_module
Drupal Project
drupal_project
Drupal Mysite
drupal_mysite
Acidfree
acidfree
Textimage
textimage
Audio Module
audio_module
Getid3
getid3
Nodefamily
nodefamily
Print Module
print_module
Forward Module
forward_module
Invite Module
invite_module
Token Module
token_module
Shoutbox
shoutbox
Feature Module
feature_module
Bueditor
bueditor
Atom Module
atom_module
Archive Module
archive_module
Workflow
workflow
Openid
openid
Header Image
header_image
Webform Module
webform_module
E Publish
e-publish
Upload Module
upload_module
Mailsave
mailsave
Mailhandler
mailhandler
Link To Us
link_to_us
Node Clone
node_clone
Stock Module
stock_module
Link Module
link_module
Storm
storm
Comment Mail
comment_mail
Tasklist
tasklist
Plus1
plus1
Feedapi Mapper
feedapi_mapper

CVEs (443)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Drupal
1Drupal
May 6, 2026
Aug 24, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading fil...Show more
Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJour...Show more
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.Show less
1Drupal
1Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Jun 22, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset UR...Show more
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.Show less
6Apache
DebianDrupal+3 more
6Debian Linux
DrillDrupal+3 more
May 6, 2026
Nov 24, 2014
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
3Debian
DrupalSecure Password Hashes Project
3Debian Linux
DrupalSecure Passwords Hashes
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) vi...Show more
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
1Drupal
1Organic Groups Menu
May 6, 2026
Nov 12, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors.
1Drupal
1Mrbs Module
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
1Drupal
1Modal Frame
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array con...Show more
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.Show less
1Drupal
1Project Issue File Review
May 6, 2026
Oct 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and return the results to the PIFR_Server test results page or (2) remote authenticated users with the "manage PIFR environments" permission to inject arbitrary web script or HTML via vectors involving a PIFR_Server administrative page.Show less
1Drupal
1Doubleclick For Publishers
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary...Show more
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.Show less
1Drupal
1Commons
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content creation and activity...Show more
Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content creation and activity stream messages.Show less
1Drupal
1Skeleton Theme
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script o...Show more
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.Show less
1Drupal
1Custom Search Module
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject ar...Show more
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.Show less
1Drupal
1Nivo Slider
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrary web script or HTML...Show more
Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrary web script or HTML via an image title.Show less
1Drupal
1Maestro
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.Show less