← Back

Drupal

drupal

443 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Drupal
drupal
Print
print
Project
project
Everyblog
everyblog
Imce Module
imce_module
Talk
talk
Views
views
Activity
activity
Data
data
Job Search
job_search
Recipe Module
recipe_module
Drupal Project
drupal_project
Drupal Mysite
drupal_mysite
Acidfree
acidfree
Textimage
textimage
Audio Module
audio_module
Getid3
getid3
Nodefamily
nodefamily
Print Module
print_module
Forward Module
forward_module
Invite Module
invite_module
Token Module
token_module
Shoutbox
shoutbox
Feature Module
feature_module
Bueditor
bueditor
Atom Module
atom_module
Archive Module
archive_module
Workflow
workflow
Openid
openid
Header Image
header_image
Webform Module
webform_module
E Publish
e-publish
Upload Module
upload_module
Mailsave
mailsave
Mailhandler
mailhandler
Link To Us
link_to_us
Node Clone
node_clone
Stock Module
stock_module
Link Module
link_module
Storm
storm
Comment Mail
comment_mail
Tasklist
tasklist
Plus1
plus1
Feedapi Mapper
feedapi_mapper

CVEs (443)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Drupal
1Drupal
Apr 29, 2026
Oct 1, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum...Show more
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.Show less
1Drupal
1Drupal
Apr 29, 2026
Oct 1, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denia...Show more
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.Show less
1Drupal
1Faq
Apr 29, 2026
Sep 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.Show less
2Drupal
Nancy Wichmann
2Realname
Realname
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page ti...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks."Show less
1Drupal
1Drupal
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Drupal
1Drupal
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error m...Show more
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.Show less
2Drupal
Nancy Wichmann
2Drupal
Glossary
Apr 29, 2026
May 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "taxonomy information."
1Drupal
1Drupal
Apr 29, 2026
May 18, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
1Drupal
1Drupal
Apr 29, 2026
Mar 28, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendo...Show more
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off.Show less
1Drupal
1Petition Node Module
Apr 29, 2026
Nov 28, 2011
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a...Show more
Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition.Show less
1Drupal
1Drupal
Apr 29, 2026
Sep 23, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-...Show more
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.Show less
1Drupal
1Drupal
Apr 29, 2026
Jul 27, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
2Drupal
Peter Wolanin
2Drupal
Openid
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentic...Show more
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.Show less
2Drupal
Peter Wolanin
2Drupal
Openid
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers...Show more
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.Show less
2Drupal
Peter Wolanin
2Drupal
Openid
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass auth...Show more
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.Show less
1Drupal
1Drupal
Apr 29, 2026
Sep 21, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action m...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.Show less
1Drupal
1Drupal
Apr 29, 2026
Sep 21, 2010
N/A· v4
N/A· v3
3.5 LOW· v2
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related...Show more
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.Show less
1Drupal
1Drupal
Apr 29, 2026
Sep 21, 2010
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended res...Show more
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.Show less
1Drupal
1Devel Module
Apr 29, 2026
Aug 16, 2010
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report acce...Show more
Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths in a URL.Show less
1Drupal
1Randomizer
Apr 23, 2026
Jan 12, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.