Drupal / Core
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-5256 | Drupal core - Critical - Cache poisoning - SA-CORE-2023-006 | HIGH | 7.5 | Sep 28, 2023 |
| CVE-2023-31250 | Drupal core - Moderately critical - Access bypass - SA-CORE-2023-005 | MEDIUM | 6.5 | Apr 26, 2023 |
| CVE-2022-25278 | Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data they should n… | MEDIUM | 6.5 | Apr 26, 2023 |
| CVE-2022-25277 | Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prev… | HIGH | 7.2 | Apr 26, 2023 |
| CVE-2022-25276 | The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. U… | MEDIUM | 6.1 | Apr 26, 2023 |
| CVE-2022-25275 | In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivativ… | HIGH | 7.5 | Apr 26, 2023 |
| CVE-2022-25274 | Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting i… | MEDIUM | 5.4 | Apr 26, 2023 |
| CVE-2022-25273 | Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow… | HIGH | 7.5 | Apr 26, 2023 |
| CVE-2022-25270 | The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission vie… | MEDIUM | 6.5 | Feb 16, 2022 |
| CVE-2022-25271 | Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow… | HIGH | 7.5 | Feb 16, 2022 |
| CVE-2020-13677 | Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. S… | HIGH | 7.5 | Feb 11, 2022 |
| CVE-2020-13676 | The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affe… | MEDIUM | 6.5 | Feb 11, 2022 |
| CVE-2020-13670 | Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they… | HIGH | 7.5 | Feb 11, 2022 |
| CVE-2020-13674 | The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible da… | MEDIUM | 6.5 | Feb 11, 2022 |
| CVE-2020-13675 | Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an acces… | CRITICAL | 9.8 | Feb 11, 2022 |
| CVE-2020-13672 | Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issu… | MEDIUM | 6.1 | Feb 11, 2022 |
| CVE-2020-13669 | Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.… | MEDIUM | 6.1 | Feb 11, 2022 |
| CVE-2020-13668 | Access bypass in Drupal Core 8/9 | MEDIUM | 6.1 | Feb 11, 2022 |
| CVE-2018-7602 KEV | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004 | CRITICAL | 9.8 | Jul 19, 2018 |
Showing 1 to 18 of 18 CVEs