Vulnerabilities > Drupal > Drupal > 8.9.7

DATE CVE VULNERABILITY TITLE RISK
2023-09-28 CVE-2023-5256 Unspecified vulnerability in Drupal
In certain scenarios, Drupal's JSON:API module will output error backtraces.
network
high complexity
drupal
7.5
2023-04-26 CVE-2022-25277 Unrestricted Upload of File with Dangerous Type vulnerability in Drupal
Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010).
network
low complexity
drupal CWE-434
7.2
2023-04-26 CVE-2022-25278 Unspecified vulnerability in Drupal
Under certain circumstances, the Drupal core form API evaluates form element access incorrectly.
network
low complexity
drupal
6.5
2023-04-26 CVE-2022-25273 Improper Input Validation vulnerability in Drupal
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation.
network
low complexity
drupal CWE-20
7.5
2023-04-26 CVE-2022-25275 Unspecified vulnerability in Drupal
In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system.
network
low complexity
drupal
7.5
2022-09-28 CVE-2022-39261 Path Traversal vulnerability in multiple products
Twig is a template language for PHP.
network
low complexity
symfony drupal fedoraproject debian CWE-22
7.5
2022-03-21 CVE-2022-24775 Improper Input Validation vulnerability in multiple products
guzzlehttp/psr7 is a PSR-7 HTTP message library.
network
low complexity
drupal guzzlephp CWE-20
5.0
2022-03-16 CVE-2022-24729 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor.
network
low complexity
ckeditor drupal oracle fedoraproject
7.5
2022-03-16 CVE-2022-24728 Cross-site Scripting vulnerability in multiple products
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor.
network
low complexity
ckeditor drupal oracle fedoraproject CWE-79
5.4
2022-02-11 CVE-2020-13672 Cross-site Scripting vulnerability in Drupal
Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances.
network
high complexity
drupal CWE-79
2.6