Drupal
drupal
443 CVEs • 143 products
Products (143)
Click to collapseToggle
Products (143)
Click to collapse
CVEs (443)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4. |
8Debian DrupalFedoraproject+5 more70Agile Product Lifecycle Management For Process Agile Product Supplier Collaboration For ProcessApplication Testing Suite+67 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted co...Show more |
7Debian DrupalFedoraproject+4 more52Active Iq Unified Manager Application ExpressApplication Testing Suite+49 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(),...Show more |
4Ckeditor DrupalFedoraproject+1 more11Agile Plm Application ExpressBanking Enterprise Default Management+8 moreJun 17, 2026 Mar 7, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected synt...Show more |
1Drupal 1Authenticated User Page Caching Nov 21, 2024 Feb 18, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to...Show more |
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. |
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display. |
1Drupal 1Views Dynamic Field Jun 17, 2026 Dec 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names obj...Show more |
1Drupal 1Views Builk Operations Nov 21, 2024 Nov 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A rem...Show more |
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. |
Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal. |
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal. |
4Debian DrupalFedoraproject+1 more4Debian Linux DrupalEnterprise Linux+1 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields...Show more |
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled. |
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blo...Show more |
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacke...Show more |
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. |
2Debian Drupal2Debian Linux DrupalNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Drupal versions 5.x and 6.x has open redirection |
2Drupal Prestashop2Drupal PrestashopJun 17, 2026 May 24, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of t...Show more |