VYPR

Vendor CVEs

Drupal

All CVEs

1,430 total · sorted by risk
  • CVE-2026-16648Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-81163Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84918Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84919Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84920Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-84921Sep 2, 2026
    risk 0.00cvss —epss —

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2025-31697MedMar 31, 2025
    risk 0.00cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0.

  • CVE-2025-31690HigMar 31, 2025
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.

  • CVE-2025-31689HigMar 31, 2025
    risk 0.00cvss 8.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.

  • CVE-2025-31687MedMar 31, 2025
    risk 0.00cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SpamSpan filter allows Cross-Site Scripting (XSS).This issue affects SpamSpan filter: from 0.0.0 before 3.2.1.

  • CVE-2018-25085LowMay 1, 2023
    risk 0.00cvss 2.4epss 0.00

    A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation…

  • CVE-2022-24775HigMar 21, 2022
    risk 0.00cvss 7.5epss 0.02

    guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known…

  • CVE-2015-8602Dec 17, 2015
    risk 0.00cvss —epss 0.01

    The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which…

  • CVE-2015-8233Nov 17, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal allows remote administrators with the "Administer themes" permission to inject arbitrary web script or HTML via unspecified vectors related to theme settings.

  • CVE-2015-8232Nov 17, 2015
    risk 0.00cvss —epss 0.01

    The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.

  • CVE-2015-8095Nov 9, 2015
    risk 0.00cvss —epss 0.01

    The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an unspecified URL pattern.

  • CVE-2015-7881Oct 26, 2015
    risk 0.00cvss —epss 0.01

    The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a comment.

  • CVE-2015-7876Oct 21, 2015
    risk 0.00cvss —epss 0.02

    The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like…

  • CVE-2015-7234Sep 17, 2015
    risk 0.00cvss —epss 0.02

    The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology and OSF Import modules are enabled, allows user-assisted remote attackers to delete arbitrary files via unspecified vectors.

  • CVE-2015-7233Sep 17, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is enabled, allows remote attackers to hijack the authentication of administrators for requests that create new OSF datasets via unspecified vectors.

  • CVE-2015-7232Sep 17, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-7231Sep 17, 2015
    risk 0.00cvss —epss 0.01

    The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a failed payment appear valid via a crafted URL, related to a "response from commweb."

  • CVE-2015-7229Sep 17, 2015
    risk 0.00cvss —epss 0.01

    The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or…

  • CVE-2015-7228Sep 17, 2015
    risk 0.00cvss —epss 0.01

    The RESTful module 7.x-1.x before 7.x-1.3 for Drupal does not properly cache pages of authenticated users when using non-cookie authentication providers, which allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2015-7227Sep 17, 2015
    risk 0.00cvss —epss 0.01

    The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.

  • CVE-2015-7226Sep 17, 2015
    risk 0.00cvss —epss 0.02

    The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.

  • CVE-2015-6921Sep 11, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-6808Sep 4, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Spotlight module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.

  • CVE-2015-6807Sep 4, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer mass contact" permission to inject arbitrary web script or HTML via a category label.

  • CVE-2015-6754Aug 31, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "Administer Path Breadcrumbs" permission to inject arbitrary web script or HTML via unspecified…

  • CVE-2015-6753Aug 31, 2015
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) entity title, related to in-place editing, or a (2) node…

  • CVE-2015-6752Aug 31, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search index is configured to use the HTML filter processor, allows remote authenticated users with certain permissions to inject arbitrary web script or…

  • CVE-2015-6751Aug 31, 2015
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2) activity used to…

  • CVE-2015-6665Aug 24, 2015
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to…

  • CVE-2015-6661Aug 24, 2015
    risk 0.00cvss —epss 0.03

    Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu.

  • CVE-2015-6660Aug 24, 2015
    risk 0.00cvss —epss 0.01

    The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

  • CVE-2015-6659Aug 24, 2015
    risk 0.00cvss —epss 0.03

    SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

  • CVE-2015-6658Aug 24, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.

  • CVE-2015-5515Aug 18, 2015
    risk 0.00cvss —epss 0.02

    The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account…

  • CVE-2015-5514Aug 18, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary web script or HTML via a destination field label.

  • CVE-2015-5510Aug 18, 2015
    risk 0.00cvss —epss 0.02

    Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration pages.

  • CVE-2015-5507Aug 18, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-5506Aug 18, 2015
    risk 0.00cvss —epss 0.02

    The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search.

  • CVE-2015-5505Aug 18, 2015
    risk 0.00cvss —epss 0.02

    The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to…

  • CVE-2015-5503Aug 18, 2015
    risk 0.00cvss —epss 0.02

    Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.

  • CVE-2015-5502Aug 18, 2015
    risk 0.00cvss —epss 0.02

    The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors.

  • CVE-2015-5500Aug 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-5499Aug 18, 2015
    risk 0.00cvss —epss 0.01

    The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveraging the "navigate view" permission.

  • CVE-2015-5497Aug 18, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-5496Aug 18, 2015
    risk 0.00cvss —epss 0.01

    The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecified vectors.

Page 12 of 29