Vulnerabilities > Drupal

DATE CVE VULNERABILITY TITLE RISK
2014-10-09 CVE-2014-8076 Cross-Site Scripting vulnerability in Drupal Professional Theme
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright information.
network
drupal CWE-79
3.5
2014-10-09 CVE-2014-8075 Cross-Site Scripting vulnerability in Drupal Tribune 6.X1.13/6.X1.2/7.X3.0
Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.
network
drupal CWE-79
3.5
2014-10-08 CVE-2014-7980 Cross-Site Scripting vulnerability in Drupal ZEN
Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.
network
drupal CWE-79
3.5
2014-10-08 CVE-2014-7979 Cross-Site Scripting vulnerability in Drupal Simplecorp 7.X1.0
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
network
drupal CWE-79
3.5
2014-10-08 CVE-2014-7978 Cross-Site Scripting vulnerability in Drupal Bluemasters 7.X2.0
Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
network
drupal CWE-79
3.5
2014-10-06 CVE-2014-7870 Cross-Site Scripting vulnerability in Drupal Custom Search Module
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom search" permission to inject arbitrary web script or HTML via the "Label text" field to admin/config/search/custom_search/results.
network
drupal CWE-79
3.5
2014-10-06 CVE-2014-7869 Cross-Site Scripting vulnerability in Drupal Context Form Alteration Module 7.X1.0/7.X1.1
Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via unspecified vectors.
network
drupal CWE-79
3.5
2014-09-30 CVE-2014-5267 Permissions, Privileges, and Access Controls vulnerability in Drupal
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
network
drupal CWE-264
6.8
2014-08-18 CVE-2014-5266 Resource Management Errors vulnerability in multiple products
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
network
low complexity
wordpress drupal debian CWE-399
5.0
2014-08-18 CVE-2014-5265 Resource Management Errors vulnerability in multiple products
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
network
low complexity
wordpress drupal debian CWE-399
5.0