Vulnerabilities > Drupal > Drupal > 7.43

DATE CVE VULNERABILITY TITLE RISK
2016-09-09 CVE-2016-6211 Permissions, Privileges, and Access Controls vulnerability in multiple products
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
network
low complexity
drupal debian CWE-264
6.5
2014-11-24 CVE-2010-5312 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
6.1