VYPR

Drupal

by Drupal

Source repositories

CVEs (335)

  • CVE-2016-9449MedNov 25, 2016
    risk 0.28cvss 4.3epss 0.02

    The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.

  • CVE-2016-7572MedOct 3, 2016
    risk 0.28cvss 4.3epss 0.02

    The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

  • CVE-2016-7570MedOct 3, 2016
    risk 0.28cvss 4.3epss 0.02

    Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

  • CVE-2025-13083LowNov 18, 2025
    risk 0.24cvss 3.7epss 0.00

    Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9,…

  • CVE-2026-15080MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.

  • CVE-2026-55807LowJul 10, 2026
    risk 0.20cvss 3.1epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to…

  • CVE-2026-15083MedJul 10, 2026
    risk 0.20cvss 4.2epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to…

  • CVE-2026-11909LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

  • CVE-2014-9016Nov 24, 2014
    risk 0.10cvss —epss 0.82

    The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

  • CVE-2005-1921Jul 5, 2005
    risk 0.09cvss —epss 0.79

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7)…

  • CVE-2014-3704Oct 16, 2014
    risk 0.04cvss —epss 1.00

    The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

  • CVE-2012-4554Nov 11, 2012
    risk 0.04cvss —epss 0.16

    The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

  • CVE-2007-6752Mar 28, 2012
    risk 0.03cvss —epss 0.04

    Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering…

  • CVE-2007-5416Oct 12, 2007
    risk 0.03cvss —epss 0.04

    Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a…

  • CVE-2005-2106Jul 5, 2005
    risk 0.03cvss —epss 0.03

    Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

  • CVE-2002-1806Dec 31, 2002
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

  • CVE-2026-84910Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84911Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84912Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84913Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

Page 8 of 17