VYPR

Vendor CVEs

Drupal

All CVEs

1,430 total · sorted by risk
  • CVE-2015-3349Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Htaccess module before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) deploy or (2) delete an .htaccess file via unspecified vectors.

  • CVE-2015-3348Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

  • CVE-2015-3347Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims via an unknown menu callback.

  • CVE-2015-3346Apr 21, 2015
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the WikiWiki module before 6.x-1.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2015-3345Apr 21, 2015
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."

  • CVE-2015-3344Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Course module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

  • CVE-2015-3343Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors.

  • CVE-2015-3342Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter.

  • CVE-2015-2559Mar 25, 2015
    risk 0.00cvss —epss 0.02

    Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

  • CVE-2015-2215Mar 5, 2015
    risk 0.00cvss —epss 0.02

    Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.

  • CVE-2015-2197Mar 3, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.

  • CVE-2015-2087Feb 26, 2015
    risk 0.00cvss —epss 0.02

    Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.

  • CVE-2015-1621Feb 17, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Webform prepopulate block module before 7.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-1568Feb 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the authentication of users with the "edit gd infinite scroll settings" permission for requests that delete settings via unspecified…

  • CVE-2015-1567Feb 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the admin page in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote authenticated users with the "edit gd infinite scroll settings" permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-1051Jan 15, 2015
    risk 0.00cvss —epss 0.02

    Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

  • CVE-2014-9505Jan 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the School Administration module 7.x-1.x before 7.x-1.8 for Drupal allows remote authenticated users with permission to create or edit a class node to inject arbitrary web script or HTML via a node title.

  • CVE-2014-9501Jan 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Poll Chart Block module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a poll node title.

  • CVE-2014-9500Jan 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Moip module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the notification page callback.

  • CVE-2014-9499Jan 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Godwin's Law module before 7.x-1.1 for Drupal, when using the dblog module, allows remote authenticated users to inject arbitrary web script or HTML via a Watchdog message.

  • CVE-2014-9498Jan 9, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Webform Invitation module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.4 for Drupal allows remote authenticated users with the Webform: Create new content, Webform: Edit own content, or Webform: Edit any content permission to…

  • CVE-2014-9364Dec 10, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Unified Login form in the LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-9363Dec 10, 2014
    risk 0.00cvss —epss 0.01

    Open redirect vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.

  • CVE-2014-9362Dec 10, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web script or HTML via vectors…

  • CVE-2014-9361Dec 10, 2014
    risk 0.00cvss —epss 0.01

    The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly obtain sensitive information by accessing a Page Not Found…

  • CVE-2014-9346Dec 8, 2014
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for…

  • CVE-2014-9156Dec 1, 2014
    risk 0.00cvss —epss 0.02

    The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.

  • CVE-2014-9155Dec 1, 2014
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.

  • CVE-2014-9154Dec 1, 2014
    risk 0.00cvss —epss 0.01

    The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

  • CVE-2014-9153Dec 1, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response.

  • CVE-2014-9152Dec 1, 2014
    risk 0.00cvss —epss 0.02

    The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.

  • CVE-2014-9151Dec 1, 2014
    risk 0.00cvss —epss 0.01

    The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

  • CVE-2014-5268Dec 1, 2014
    risk 0.00cvss —epss 0.01

    The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link.

  • CVE-2014-9015Nov 24, 2014
    risk 0.00cvss —epss 0.02

    Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

  • CVE-2014-9026Nov 20, 2014
    risk 0.00cvss —epss 0.01

    The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.

  • CVE-2014-9025Nov 20, 2014
    risk 0.00cvss —epss 0.01

    The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at checkout, which allows remote attackers to obtain sensitive information via…

  • CVE-2014-9024Nov 20, 2014
    risk 0.00cvss —epss 0.01

    The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path.

  • CVE-2014-9023Nov 20, 2014
    risk 0.00cvss —epss 0.01

    The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify authentication tokens by leveraging the "access administration pages" Drupal permission.

  • CVE-2014-9022Nov 20, 2014
    risk 0.00cvss —epss 0.02

    The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" restriction and modify read-only components via a crafted form.

  • CVE-2012-2301Nov 16, 2014
    risk 0.00cvss —epss 0.01

    The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.

  • CVE-2014-8736Nov 12, 2014
    risk 0.00cvss —epss 0.01

    The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node.

  • CVE-2014-8735Nov 12, 2014
    risk 0.00cvss —epss 0.01

    The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords, which allows remote authenticated users with the "administer bad behavior" permission to obtain sensitive information by reading a log file.

  • CVE-2014-8734Nov 12, 2014
    risk 0.00cvss —epss 0.01

    The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal allows remote authenticated users with the "access administration pages" permission to change module settings via unspecified vectors.

  • CVE-2013-7407Oct 22, 2014
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2013-7406Oct 21, 2014
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2014-5169Oct 20, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title.

  • CVE-2014-8320Oct 17, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the "Label text" field to the results…

  • CVE-2014-8296Oct 16, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-8765Oct 14, 2014
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and…

  • CVE-2014-8748Oct 13, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.

Page 15 of 29