Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal project vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2008-0576
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev prior to 20080130 in the 5.x-2.x series, 5.x-1.2 and previous versions in the 5.x-1.x series, 4.7.x-2.6 and previous versions in the 4.7.x-2.x series, and 4.7.x-1.6 and previous versions in ...
Drupal Project Issue Tracking Module 5
Drupal Project Issue Tracking Module 4.7
570
VMScore
CVE-2008-0577
The Project Issue Tracking module 5.x-2.x-dev prior to 20080130 in the 5.x-2.x series, 5.x-1.2 and previous versions in the 5.x-1.x series, 4.7.x-2.6 and previous versions in the 4.7.x-2.x series, and 4.7.x-1.6 and previous versions in the 4.7.x-1.x series for Drupal (1) does not...
Drupal Project Issue Tracking Module 4.7
Drupal Project Issue Tracking Module 5.0
383
VMScore
CVE-2006-2260
Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote malicious users to inject arbitrary web script or HTML via unknown attack vectors.
Drupal Drupal 4.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.5.1
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
454
VMScore
CVE-2015-5508
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote malicious users to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP ...
The Extensible Catalog Drupal Toolkit Project The Extensible Catalog Drupal Toolkit -
312
VMScore
CVE-2010-3093
The comment module in Drupal 5.x prior to 5.23 and 6.x prior to 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.
Drupal Drupal 5.4
Drupal Drupal 5.5
Drupal Drupal 5.6
Drupal Drupal 5.7
Drupal Drupal 5.20
Drupal Drupal 5.21
Drupal Drupal 5.22
Drupal Drupal 5.0
Drupal Drupal 5.12
Drupal Drupal 5.13
Drupal Drupal 5.14
Drupal Drupal 5.15
Drupal Drupal 5.1
Drupal Drupal 5.3
Drupal Drupal 5.8
Drupal Drupal 5.10
Drupal Drupal 5.17
Drupal Drupal 5.19
Drupal Drupal 5.2
Drupal Drupal 5.9
Drupal Drupal 5.11
Drupal Drupal 5.16
490
VMScore
CVE-2010-3092
The upload module in Drupal 5.x prior to 5.23 and 6.x prior to 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different...
Drupal Drupal 5.0
Drupal Drupal 5.10
Drupal Drupal 5.11
Drupal Drupal 5.12
Drupal Drupal 5.13
Drupal Drupal 5.14
Drupal Drupal 5.2
Drupal Drupal 5.3
Drupal Drupal 5.4
Drupal Drupal 5.5
Drupal Drupal 5.19
Drupal Drupal 5.20
Drupal Drupal 5.21
Drupal Drupal 5.22
Drupal Drupal 5.1
Drupal Drupal 5.6
Drupal Drupal 5.8
Drupal Drupal 5.15
Drupal Drupal 5.17
Drupal Drupal 5.7
Drupal Drupal 5.9
Drupal Drupal 5.16
187
VMScore
CVE-2010-3094
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x prior to 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the...
Drupal Drupal 6.0
Drupal Drupal 6.9
Drupal Drupal 6.10
Drupal Drupal 6.11
Drupal Drupal 6.12
Drupal Drupal 6.13
Drupal Drupal 6.1
Drupal Drupal 6.2
Drupal Drupal 6.3
Drupal Drupal 6.4
Drupal Drupal 6.6
Drupal Drupal 6.8
Drupal Drupal 6.15
Drupal Drupal 6.17
Drupal Drupal 6.5
Drupal Drupal 6.7
Drupal Drupal 6.14
Drupal Drupal 6.16
383
VMScore
CVE-2009-2373
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x prior to 6.13 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal 6.3
Drupal Drupal 6.0
Drupal Drupal 5.14
Drupal Drupal 5.16
Drupal Drupal 5.2
Drupal Drupal 5.8
Drupal Drupal 6.8
Drupal Drupal 6.10
Drupal Drupal 6.9
Drupal Drupal 6.12
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 5.13
Drupal Drupal 5.3
Drupal Drupal 5.5.
Drupal Drupal 5.4
Drupal Drupal 5.0
Drupal Drupal 6.6
Drupal Drupal 6.7
Drupal Drupal 6.5
Drupal Drupal 6.4
Drupal Drupal 5.1
Drupal Drupal 5.9
409
VMScore
CVE-2006-1227
Drupal 4.5.x prior to 4.5.8 and 4.6.x prior to 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote malicious users to access administrator pages.
Drupal Drupal 4.5.6
Drupal Drupal 4.5.7
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.5.0
Drupal Drupal 4.5.1
Drupal Drupal 4.6.0
Drupal Drupal 4.6.1
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
Drupal Drupal 4.6.4
Drupal Drupal 4.6.5
570
VMScore
CVE-2005-3974
Drupal 4.5.0 up to and including 4.5.5 and 4.6.0 up to and including 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote malicious users to bypass the "access user profiles" permission.
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
Drupal Drupal 4.5
Drupal Drupal 4.5.1
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »