Vulnerabilities > Drupal > Drupal > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-11 | CVE-2020-13672 | Cross-site Scripting vulnerability in Drupal Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. | 2.6 |
2019-11-07 | CVE-2010-2472 | Cross-site Scripting vulnerability in Drupal Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. | 3.5 |
2019-11-07 | CVE-2010-2473 | Improper Input Validation vulnerability in Drupal Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. | 3.5 |
2019-05-16 | CVE-2019-10909 | Cross-site Scripting vulnerability in multiple products In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. | 3.5 |
2018-03-01 | CVE-2017-6928 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. | 3.5 |
2015-03-25 | CVE-2015-2559 | Improper Access Control vulnerability in multiple products Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL. | 3.5 |
2014-07-22 | CVE-2014-5021 | Cross-Site Scripting vulnerability in Drupal Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label. | 2.1 |
2014-05-20 | CVE-2013-4380 | Cross-Site Scripting vulnerability in Mediafront Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings. | 2.1 |
2014-05-17 | CVE-2013-4498 | Permissions, Privileges, and Access Controls vulnerability in Florian Weber Spaces The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content. | 2.1 |
2014-05-13 | CVE-2013-4504 | Permissions, Privileges, and Access Controls vulnerability in Monster Menus Module Project Monster Menus The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL. | 2.6 |