VYPR

Views Bulk Operations

by Drupal

CVEs (5)

  • CVE-2011-3373MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that…

  • CVE-2015-5515Aug 18, 2015
    risk 0.00cvss epss 0.02

    The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account…

  • CVE-2010-5277Oct 7, 2012
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.

  • CVE-2009-2237Jun 27, 2009
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered…

  • CVE-2009-0575Feb 13, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or…