Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2012-5543

Published Dec 3, 2012

The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to creat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5540

Published Dec 3, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Hostip module 6.x-2.x before 6.x-2.2 and 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers with control of hostip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4474

Published Nov 30, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4472

Published Nov 30, 2012

Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uplo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4470

Published Nov 30, 2012

The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment authors to bypass access restrictio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4469

Published Nov 30, 2012

Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2084

Published Nov 22, 2012

Cross-site scripting (XSS) vulnerability in the Printer, email and PDF versions module 6.x-1.x before 6.x-1.15 and 7.x-1.x before 7.x-1.0 for Drupal allows remote attackers to inj…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4554

Published Nov 11, 2012

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-4553

Published Nov 11, 2012

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, relat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4498

Published Nov 2, 2012

The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restric…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4497

Published Nov 2, 2012

Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "adminis…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4493

Published Nov 2, 2012

Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with th…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 326-350 of 866 CVEsPage 14 of 35