Drupal
drupal
443 CVEs • 143 products
Products (143)
Click to collapseToggle
Products (143)
Click to collapse
CVEs (443)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This i...Show more |
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9...Show more |
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior t...Show more |
3Ckeditor DrupalOracle9Agile Product Lifecycle Management Application ExpressBanking Apis+6 moreJun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inje...Show more |
4Ckeditor DrupalFedoraproject+1 more10Agile Plm Application ExpressBanking Apis+7 moreJun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allow...Show more |
6Drupal FedoraprojectJqueryui+3 more27Agile Plm Application ExpressBanking Platform+24 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in...Show more |
7Debian DrupalFedoraproject+4 more28Agile Plm Application ExpressBanking Platform+25 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fi...Show more |
7Debian DrupalFedoraproject+4 more29Agile Plm Application ExpressBanking Platform+26 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixe...Show more |
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities. |
Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions...Show more |
4Ckeditor DebianDrupal+1 more4Ckeditor Debian LinuxDrupal+1 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!>...Show more |
Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leadi...Show more |
Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Dru...Show more |
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on...Show more |
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70...Show more |
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does not disable JSONP by default, allowing for an XSS attack. This issue affects: Drupal Drupal Core 7.x versions prior to 7.73; 8.8.x versions prior to...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Jan 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. |
1Drupal 1Drupal Docker Images Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow...Show more |
2Drupal Fedoraproject2Drupal FedoraJun 17, 2026 Nov 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting co...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed. |