VYPR

Vendor CVEs

Drupal

All CVEs

1,430 total · sorted by risk
  • CVE-2024-13293LowJan 9, 2025
    risk 0.20cvss 3.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.

  • CVE-2026-8492LowMay 19, 2026
    risk 0.18cvss 2.7epss 0.00

    Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.

  • CVE-2026-81168LowSep 2, 2026
    risk 0.17cvss 3.7epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

  • CVE-2012-10004LowJan 11, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file basic_cart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the…

  • CVE-2026-13235LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

  • CVE-2026-13233LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.

  • CVE-2026-11909LowJul 10, 2026
    risk 0.14cvss 3.3epss 0.00

    Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

  • CVE-2014-9016Nov 24, 2014
    risk 0.10cvss —epss 0.82

    The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

  • CVE-2005-1921Jul 5, 2005
    risk 0.09cvss —epss 0.79

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7)…

  • CVE-2014-3704Oct 16, 2014
    risk 0.04cvss —epss 1.00

    The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

  • CVE-2012-4554Nov 11, 2012
    risk 0.04cvss —epss 0.16

    The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

  • CVE-2007-6752Mar 28, 2012
    risk 0.03cvss —epss 0.04

    Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering…

  • CVE-2009-4429Dec 28, 2009
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).

  • CVE-2008-5998Jan 28, 2009
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to…

  • CVE-2008-2629Jun 10, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.

  • CVE-2007-5416Oct 12, 2007
    risk 0.03cvss —epss 0.04

    Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a…

  • CVE-2006-2883Jun 7, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

  • CVE-2006-2884Jun 7, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in Kmita FAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

  • CVE-2005-2106Jul 5, 2005
    risk 0.03cvss —epss 0.03

    Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

  • CVE-2002-1806Dec 31, 2002
    risk 0.03cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

  • CVE-2026-84910Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84911Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84912Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84913Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84914Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84915Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87936Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87937Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87938Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87939Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87940Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87941Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87942Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87943Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87944Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87945Sep 10, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87946Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87947Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87948Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87949Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87950Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87951Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87952Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87953Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87954Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87955Sep 9, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84923Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84924Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84916Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84917Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

Page 11 of 29