Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2009-3488

Published Sep 30, 2009

Cross-site scripting (XSS) vulnerability in the Bibliography (aka Biblio) module 6.x-1.6 for Drupal allows remote authenticated users, with certain content-creation privileges, to…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3479

Published Sep 30, 2009

Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows remote attackers, with "create content di…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3442

Published Sep 28, 2009

The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows remote attackers to obtain se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3435

Published Sep 28, 2009

Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inj…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3363

Published Sep 24, 2009

Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3352

Published Sep 24, 2009

Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3210

Published Sep 16, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x before 6.x-1.8, a module for Drupal, allo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3207

Published Sep 16, 2009

The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for der…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3206

Published Sep 16, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated user…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3157

Published Sep 10, 2009

Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inj…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3156

Published Sep 10, 2009

Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3121

Published Sep 9, 2009

Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7151

Published Sep 1, 2009

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7150

Published Sep 1, 2009

Cross-site scripting (XSS) vulnerability in Refine by Taxonomy 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a taxono…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6910

Published Aug 6, 2009

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6909

Published Aug 6, 2009

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6908

Published Aug 6, 2009

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 626-650 of 866 CVEsPage 26 of 35