Skip to content
Noroxi

Drupal records

863 published records for vendor drupal.

All records

863 records
  • Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    drupal · drupalMar 29, 2018

  • Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    drupal · drupalJul 19, 2018

  • Drupal core - Highly critical - Remote Code Execution

    HighCVSS 8.1KEVWeaponizedEPSS 92%

    drupal · drupalFeb 21, 2019

  • Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    HighCVSS 7.8KEVWeaponizedEPSS 85%

    php · archive tarNov 19, 2020

  • Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat

    HighCVSS 7.5KEVWeaponizedEPSS 71%

    php · archive tarJan 18, 2021

  • CVE-2020-11023
    79This week

    Potential XSS vulnerability in jQuery

    MediumCVSS 6.1KEVWeaponizedEPSS 85%

    jquery · jqueryApr 29, 2020

  • CVE-2020-13671
    76This week

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten

    HighCVSS 8.8KEVWeaponizedEPSS 35%

    drupal · drupalNov 20, 2020

  • CVE-2026-9082
    74This week

    Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

    CriticalCVSS 9.8KEVWeaponizedEPSS 16%

    drupal · drupalMay 20, 2026

  • CVE-2014-3704
    60This week

    The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,

    HighCVSS 7.5WeaponizedEPSS 100%

    drupal · drupalOct 15, 2014

  • jQuery has a potential XSS vulnerability

    MediumCVSS 6.1Proof of conceptEPSS 99%

    jquery · jqueryApr 29, 2020

  • Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1

    HighCVSS 7.5WeaponizedEPSS 79%

    php · xml rpcJul 5, 2005

  • jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp

    MediumCVSS 6.1Proof of conceptEPSS 87%

    jquery · jqueryApr 19, 2019

  • PHAR stream wrapper Arbitrary PHP code execution

    CriticalCVSS 9.8Proof of conceptEPSS 36%

    drupal · drupalJan 22, 2019

  • Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

    HighCVSS 7.5Proof of conceptEPSS 55%

    drupal · avatar uploaderApr 4, 2018

  • PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t

    HighCVSS 8.1No exploitEPSS 50%

    hp · storeever msl6480 tape library firmwareJul 18, 2016

  • The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allo

    MediumCVSS 5.0WeaponizedEPSS 82%

    drupal · drupalNov 24, 2014

  • Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

    HighCVSS 7.8Proof of conceptEPSS 47%

    php · archive tarNov 19, 2020

  • Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s

    CriticalCVSS 9.8No exploitEPSS 20%

    drupal · drupalAug 6, 2018

  • An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13

    MediumCVSS 6.5No exploitEPSS 58%

    sensiolabs · symfonyAug 3, 2018

  • In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inp

    CriticalCVSS 9.8No exploitEPSS 6%

    sensiolabs · symfonyMay 16, 2019

  • The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal

    CriticalCVSS 9.8No exploitEPSS 5%

    typo3 · pharstreamwrapperMay 9, 2019

  • Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attacker

    CriticalCVSS 10.0No exploitEPSS 2%

    drupal · secure site moduleFeb 4, 2008

  • Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vi

    CriticalCVSS 10.0No exploitEPSS 2%

    drupal · header imageFeb 19, 2008

  • The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended res

    CriticalCVSS 10.0No exploitEPSS 2%

    drupal · drupalMar 27, 2013

  • Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 2%

    drupal · drupalSep 24, 2009