Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2012-5653

Published Jan 3, 2013

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a nul…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5652

Published Jan 3, 2013

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5651

Published Jan 3, 2013

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5589

Published Dec 26, 2012

The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5588

Published Dec 26, 2012

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, doe…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5587

Published Dec 26, 2012

Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5586

Published Dec 26, 2012

The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary u…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5585

Published Dec 26, 2012

Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permissio…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5584

Published Dec 26, 2012

The Table of Contents module 6.x-3.x before 6.x-3.8 for Drupal does not properly check node permissions, which allows remote attackers to read a node's headers by accessing a tabl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6065

Published Dec 3, 2012

The OM Maximenu module 6.x-1.43 and earlier for Drupal, when the "Title has PHP" option is enabled, allows remote authenticated users with the "Administer OM Maximenu" permission…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5553

Published Dec 3, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal allow remote authenticated users with…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5552

Published Dec 3, 2012

The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "clie…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5551

Published Dec 3, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to inject arbitrary web script or HTML via vec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5549

Published Dec 3, 2012

Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unk…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5548

Published Dec 3, 2012

Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5547

Published Dec 3, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijack the authentication of admini…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5545

Published Dec 3, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the ShareThis module 7.x-2.x before 7.x-2.5 for Drupal allow remote authenticated users with the "administer sharethis" perm…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5544

Published Dec 3, 2012

The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 866 CVEsPage 13 of 35