Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal project vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-6646
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters, which do not use t...
Drupal Drupal Project 4.7
Drupal Drupal Project 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project 4.6
Drupal Drupal Project 4.7 2.0
Drupal Drupal Project 4.6 1.0
NA
CVE-2007-1368
The Project issue tracking module prior to 4.7.x-1.3, 4.7.x-2.* prior to 4.7.x-2.3, and 5 prior to 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node i...
Drupal Drupal Project Issue Tracking 4.7 2.1
Drupal Drupal Project Issue Tracking 5.0 0.1
Drupal Drupal Project Issue Tracking 5.7 1.1
Drupal Drupal Project Issue Tracking 4.7 1.2
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.2
NA
CVE-2007-5228
Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module prior to 4.7.x-1.5, 4.7.x-2.x prior to 4.7.x-2.5, and 5.x-1.x prior to 5.x-1.1 for Drupal allows remote authenticated users with project create or edit permissions to i...
Drupal Drupal Project Issue Tracking 4.7 2.1
Drupal Drupal Project Issue Tracking 5.0 0.1
Drupal Drupal Project Issue Tracking 4.7 1.2
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.2
NA
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project Issue Tracking Module 4.7
Drupal Project 5.0
Drupal Project Issue Tracking Module 5.0
Drupal Project 4.7 2.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.6
Drupal Project 4.7 1.1
Drupal Project 4.6 1.1
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project 4.7
NA
CVE-2007-0506
The project_issue_access function in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue informat...
Drupal Project Issue Tracking Module 4.7
Drupal Project 5.0
Drupal Project Issue Tracking Module 5.0
Drupal Project 4.7 2.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.6
Drupal Project 4.7 1.1
Drupal Project 4.6 1.1
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project 4.7
6.1
CVSSv3
CVE-2015-7943
Open redirect vulnerability in the Overlay module in Drupal 7.x prior to 7.41, the jQuery Update module 7.x-2.x prior to 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x prior to 7.x-1.8 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing a...
Drupal Drupal 7.0
Drupal Drupal 7.39
Drupal Drupal 7.40
Drupal Drupal 7.16
Drupal Drupal 7.21
Drupal Drupal 7.18
Drupal Drupal 7.15
Drupal Drupal 7.38
Drupal Drupal 7.3
Drupal Drupal 7.17
Drupal Drupal 7.8
Drupal Drupal 7.13
Drupal Drupal 7.35
Drupal Drupal 7.20
Drupal Drupal 7.5
Drupal Drupal 7.10
Drupal Drupal 7.30
Drupal Drupal 7.27
Drupal Drupal 7.6
Drupal Drupal 7.12
Drupal Drupal 7.34
Drupal Drupal 7.9
NA
CVE-2015-6665
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x prior to 7.39 and the Ctools module 6.x-1.x prior to 6.x-1.14 for Drupal allows remote malicious users to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly rela...
Fedoraproject Fedora 22
Fedoraproject Fedora 23
Fedoraproject Fedora 21
Drupal Drupal 7.0
Drupal Drupal 7.16
Drupal Drupal 7.21
Drupal Drupal 7.18
Drupal Drupal 7.15
Drupal Drupal 7.38
Drupal Drupal 7.3
Drupal Drupal 7.17
Drupal Drupal 7.8
Drupal Drupal 7.13
Drupal Drupal 7.35
Drupal Drupal 7.20
Drupal Drupal 7.5
Drupal Drupal 7.10
Drupal Drupal 7.30
Drupal Drupal 7.27
Drupal Drupal 7.6
Drupal Drupal 7.12
Drupal Drupal 7.34
NA
CVE-2007-0534
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 up to and including 5.x prior to 20070123 and (2) Project 4.6.0 up to and including 5.x prior to 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script...
Drupal Project Issue Tracking Module 4.7.0
Drupal Project Issue Tracking Module
Drupal Project
Drupal Project 4.6.0
NA
CVE-2014-8765
Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x prior to 6.x-2.17 for Drupal allow (1) remote malicious users to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the pat...
Drupal Project Issue File Review 6.x-2.12
Drupal Project Issue File Review 6.x-2.01
Drupal Project Issue File Review 6.x-2.14
Drupal Project Issue File Review 6.x-2.00
Drupal Project Issue File Review 6.x-2.08
Drupal Project Issue File Review 6.x-2.06
Drupal Project Issue File Review 6.x-2.13
Drupal Project Issue File Review 6.x-2.15
Drupal Project Issue File Review
Drupal Project Issue File Review 6.x-2.07
Drupal Project Issue File Review 6.x-2.03
Drupal Project Issue File Review 6.x-2.02
Drupal Project Issue File Review 6.x-2.04
Drupal Project Issue File Review 6.x-2.05
Drupal Project Issue File Review 6.x-2.10
NA
CVE-2007-4436
The Drupal Project module prior to 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module prior to 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote malicious users to (1) obtain sensitive via the Tracker Module and the Recent...
Drupal Project Issue Tracking Module
Drupal Project
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »