entity api project records
7 published records for vendor entity api project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2014-1398No exploit | The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass inentity api project · entity api · CWE-284 | Medium6.5 | — | 1.4% | Apr 10, 2018 |
26Monitor | CVE-2014-1400No exploit | The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended aentity api project · entity api · CWE-284 | Medium6.5 | — | 1.4% | Apr 10, 2018 |
26Monitor | CVE-2014-1399No exploit | The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass inentity api project · entity api · CWE-284 | Medium6.5 | — | 1.4% | Apr 10, 2018 |
21Monitor | CVE-2026-81158No exploit | Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113entity api project · entity api · CWE-863 | Medium5.3 | — | 0.3% | Sep 2, 2026 |
20Monitor | CVE-2013-7391No exploit | The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to readentity api project · entity api · CWE-264 | Medium5.0 | — | 1.4% | Jul 19, 2014 |
16Monitor | CVE-2013-4273No exploit | The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticateentity api project · entity api · CWE-264 | Medium4.0 | — | 1.1% | Jul 19, 2014 |
14Monitor | CVE-2015-2197No exploit | Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbientity api project · entity api · CWE-79 | Low3.5 | — | 1.4% | Mar 3, 2015 |
- CVE-2014-139826Monitor
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass in
MediumCVSS 6.5No exploitEPSS 1%entity api project · entity apiApr 10, 2018
- CVE-2014-140026Monitor
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended a
MediumCVSS 6.5No exploitEPSS 1%entity api project · entity apiApr 10, 2018
- CVE-2014-139926Monitor
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass in
MediumCVSS 6.5No exploitEPSS 1%entity api project · entity apiApr 10, 2018
- CVE-2026-8115821Monitor
Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
MediumCVSS 5.3No exploitEPSS 0%entity api project · entity apiSep 2, 2026
- CVE-2013-739120Monitor
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read
MediumCVSS 5.0No exploitEPSS 1%entity api project · entity apiJul 19, 2014
- CVE-2013-427316Monitor
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticate
MediumCVSS 4.0No exploitEPSS 1%entity api project · entity apiJul 19, 2014
- CVE-2015-219714Monitor
Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbi
LowCVSS 3.5No exploitEPSS 1%entity api project · entity apiMar 3, 2015