Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 5.x vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2008-10004
A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to sql injection. The attack ...
Email Registration Project Email Registration 5.x-2.1
5.4
CVSSv3
CVE-2013-4275
Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x prior to 7.x-3.2, and 7.x-5.x prior to 7.x-5.4 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitr...
Zen Project Zen
4.8
CVSSv3
CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x prior to 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an malicious user to perform a cross-site scripting (XSS) attack. Th...
Drupal Drupal
6.5
CVSSv3
CVE-2010-2473
Drupal 6.x prior to 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
Drupal Drupal
6.1
CVSSv3
CVE-2010-2250
Drupal 5.x and 6.x prior to 6.16 uses a user-supplied value in output during site installation which could allow an malicious user to craft a URL and perform a cross-site scripting attack.
Drupal Drupal
6.1
CVSSv3
CVE-2010-2471
Drupal versions 5.x and 6.x has open redirection
Drupal Drupal
Debian Debian Linux 5.0
6.1
CVSSv3
CVE-2019-11358
jQuery prior to 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Jquery Jquery
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Drupal Drupal
Backdropcms Backdrop
Fedoraproject Fedora 28
Fedoraproject Fedora 29
Fedoraproject Fedora 30
Opensuse Leap 15.1
Opensuse Backports Sle 15.0
Netapp Snapcenter -
Netapp Oncommand System Manager
Redhat Cloudforms 4.7
Redhat Virtualization Manager 4.3
Oracle Service Bus 12.1.3.0.0
Oracle Primavera Unifier 16.2
Oracle Jd Edwards Enterpriseone Tools 9.2
Oracle Weblogic Server 12.1.3.0.0
Oracle Service Bus 11.1.1.9.0
Oracle Jdeveloper 11.1.1.9.0
Oracle Primavera Unifier 16.1
129 Github repositories
NA
CVE-2015-7229
The Twitter module 6.x-5.x prior to 6.x-5.2, 7.x-5.x prior to 7.x-5.9, and 7.x-6.x prior to 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter"...
Twitter Project Twitter 7.x-5.1
Twitter Project Twitter 7.x-5.2
Twitter Project Twitter 7.x-5.3
Twitter Project Twitter 7.x-5.4
Twitter Project Twitter 7.x-6.0
Twitter Project Twitter 6.x-5.x
Twitter Project Twitter 7.x-5.0
Twitter Project Twitter 7.x-5.5
Twitter Project Twitter 7.x-5.7
Twitter Project Twitter 6.x-5.0
Twitter Project Twitter 6.x-5.1
Twitter Project Twitter 7.x-5.6
Twitter Project Twitter 7.x-5.8
NA
CVE-2014-7980
Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x prior to 7.x-3.3 and 7.x-5.x prior to 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip...
Drupal Zen 7.x-5.3
Drupal Zen 7.x-5.2
Drupal Zen 7.x-5.1
Drupal Zen 7.x-5.0
Drupal Zen 7.x-3.2
Drupal Zen 7.x-3.0
Drupal Zen 7.x-3.1
Drupal Zen 7.x-5.4
NA
CVE-2012-5654
The Nodewords: D6 Meta Tags module prior to 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote malicious users to obtain sensitive information by r...
Nodewords Project Nodewords 6.x-1.12
Nodewords Project Nodewords 6.x-1.3
Nodewords Project Nodewords 5.x-1.7
Nodewords Project Nodewords 5.x-1.5
Nodewords Project Nodewords 5.x-1.4
Nodewords Project Nodewords 5.x-1.3
Nodewords Project Nodewords 6.x-1.14
Nodewords Project Nodewords 6.x-1.13
Nodewords Project Nodewords 6.x-1.9
Nodewords Project Nodewords 6.x-1.8
Nodewords Project Nodewords 6.x-1.7
Nodewords Project Nodewords 6.x-1.6
Nodewords Project Nodewords
Nodewords Project Nodewords 5.x-1.13
Nodewords Project Nodewords 5.x-1.12
Nodewords Project Nodewords 5.x-1.11
Nodewords Project Nodewords 4.7-1.1
Nodewords Project Nodewords 4.7-1.0
Nodewords Project Nodewords 4.7-1.x
Nodewords Project Nodewords 6.x-1.10
Nodewords Project Nodewords 6.x-1.5
Nodewords Project Nodewords 6.x-1.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »