Vulnerabilities > Drupal

DATE CVE VULNERABILITY TITLE RISK
2019-01-15 CVE-2017-6924 Improper Privilege Management vulnerability in Drupal
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments.
network
high complexity
drupal CWE-269
7.4
2019-01-15 CVE-2017-6925 Unspecified vulnerability in Drupal
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities.
network
low complexity
drupal
critical
9.8
2018-08-06 CVE-2017-6920 Data Processing Errors vulnerability in Drupal
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
network
low complexity
drupal CWE-19
critical
9.8
2018-08-03 CVE-2018-14773 An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2.
network
low complexity
sensiolabs debian drupal
6.5
2018-07-19 CVE-2018-7602 A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x.
network
low complexity
drupal debian
critical
9.8
2018-04-19 CVE-2018-9861 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
network
low complexity
ckeditor drupal CWE-79
6.1
2018-04-04 CVE-2018-9205 Path Traversal vulnerability in Drupal Avatar Uploader 7.X1.0
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
network
low complexity
drupal CWE-22
7.5
2018-03-29 CVE-2014-5170 Improper Input Validation vulnerability in Drupal Storage API
The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.
network
low complexity
drupal CWE-20
critical
9.8
2018-03-29 CVE-2018-7600 Improper Input Validation vulnerability in multiple products
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
network
low complexity
drupal debian CWE-20
critical
9.8
2018-03-01 CVE-2017-6932 Open Redirect vulnerability in multiple products
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used.
network
high complexity
drupal debian CWE-601
4.7