Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal views vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-2076
Cross-site scripting (XSS) vulnerability in Views 6.x prior to 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define ...
Drupal Views 6.x-2.0
Drupal Views 6.x-2.1
Drupal Views 6.x-2.2
Drupal Views 6.x-2.3
Drupal Views 6.x-2.4
Drupal Views 6.x-2.5
NA
CVE-2009-0575
Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x prior to 5.x-1.3 and 6.x prior to 6.x-1.4, a module for Drupal, allows remote malicious users to inject arbitrary web scr...
Drupal Views Bulk Operations 5.x-1.0beta3
Drupal Views Bulk Operations 6.x-1.1
Drupal Views Bulk Operations 6.x-1.2
Drupal Views Bulk Operations 5.x-1.0beta1
Drupal Views Bulk Operations 5.x-1.1
Drupal Views Bulk Operations
Drupal Views Bulk Operations 6.x-1.0
Drupal Views Bulk Operations 5.x-1.0beta4
Drupal Views Bulk Operations 5.x-1.0beta5
Drupal Views Bulk Operations 5.x-1.0
NA
CVE-2008-6020
SQL injection vulnerability in the Views module 6.x prior to 6.x-2.2 for Drupal allows remote malicious users to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK text fields."
Drupal Views
Drupal Views 6.x-2.0
9.8
CVSSv3
CVE-2019-19826
The Views Dynamic Fields module up to and including 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion...
Drupal Views Dynamic Field
Drupal Views Dynamic Field 7.x-1.0
6.1
CVSSv3
CVE-2011-3373
Drupal Views Builk Operations (VBO) module 6.x-1.0 up to and including 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially...
Drupal Views Builk Operations
NA
CVE-2015-3379
The Views module prior to 6.x-2.18, 6.x-3.x prior to 6.x-3.2, and 7.x-3.x prior to 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Views Project Views 6.x-3.0
Views Project Views 7.x-3.6
Views Project Views 7.x-3.7
Views Project Views 7.x-3.8
Views Project Views 7.x-3.x
Views Project Views 7.x-3.0
Views Project Views 7.x-3.1
Views Project Views
Views Project Views 7.x-3.2
Views Project Views 7.x-3.4
Views Project Views 7.x-3.3
Views Project Views 7.x-3.5
NA
CVE-2015-3378
Open redirect vulnerability in the Views module prior to 6.x-2.18, 6.x-3.x prior to 6.x-3.2, and 7.x-3.x prior to 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks v...
Views Project Views 6.x-3.0
Views Project Views 7.x-3.0
Views Project Views 7.x-3.1
Views Project Views 7.x-3.8
Views Project Views 7.x-3.x
Views Project Views 7.x-3.4
Views Project Views 7.x-3.5
Views Project Views
Views Project Views 7.x-3.2
Views Project Views 7.x-3.3
Views Project Views 7.x-3.6
Views Project Views 7.x-3.7
NA
CVE-2015-5490
The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 up to and including 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote malicious users to bypass intended filters and obtain access to hidden cont...
Views Project Views 7.x-3.8
Views Project Views 7.x-3.10
Views Project Views 7.x-3.5
Views Project Views 7.x-3.6
Views Project Views 7.x-3.7
NA
CVE-2015-7226
The Administration Views module 7.x-1.x prior to 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote malicious users to obtain sensitive information via vectors related to the access handler.
Administration Views Project Administration Views 7.x-1.x
Administration Views Project Administration Views 7.x-1.3
Administration Views Project Administration Views 7.x-1.4
Administration Views Project Administration Views 7.x-1.1
Administration Views Project Administration Views 7.x-1.2
Administration Views Project Administration Views 7.x-1.0
NA
CVE-2011-4113
SQL injection vulnerability in the Views module prior to 6.x-2.13 for Drupal allows remote malicious users to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."
Earl Miles Views 6.x-2.9
Earl Miles Views 6.x-2.8
Earl Miles Views 6.x-2.1
Earl Miles Views 6.x-2.0
Earl Miles Views 5.x-1.8
Earl Miles Views 5.x-1.7
Earl Miles Views 5.x-1.5
Earl Miles Views 5.x-1.4-2
Earl Miles Views 4.7.x-1.6
Earl Miles Views 4.7.x-1.2
Earl Miles Views 4.7.x-1.1
Earl Miles Views
Earl Miles Views 6.x-2.5
Earl Miles Views 6.x-2.4
Earl Miles Views 5.x-1.6
Earl Miles Views 6.x-2.11
Earl Miles Views 6.x-2.10
Earl Miles Views 6.x-2.3
Earl Miles Views 6.x-2.2
Earl Miles Views 6.x-2.x
Earl Miles Views 5.x-1.1
Earl Miles Views 5.x-1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »