Software
drupal
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
60
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2009-3354 | 10.0 | HIGH | Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors. |
| CVE-2009-3353 | 10.0 | HIGH | Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors. |
| CVE-2009-3352 | 10.0 | HIGH | Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors. |
| CVE-2009-3351 | 10.0 | HIGH | Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors. |
| CVE-2009-3350 | 10.0 | HIGH | Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors. |
| CVE-2013-0318 | 10.0 | HIGH | The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspec... |
| CVE-2011-2715 | 9.8 | N/A | An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. |
| CVE-2017-6920 | 9.8 | N/A | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain... |
| CVE-2017-6925 | 9.8 | N/A | In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or d... |
| CVE-2018-7600 | 9.8 | N/A | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting... |
| CVE-2018-7602 | 9.8 | N/A | A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vect... |
| CVE-2019-10910 | 9.8 | N/A | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow... |
| CVE-2019-11831 | 9.8 | N/A | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attac... |
| CVE-2019-6339 | 9.8 | N/A | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar st... |
| CVE-2019-6342 | 9.8 | N/A | An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces mod... |
| CVE-2020-13665 | 9.8 | N/A | Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.se... |
| CVE-2020-13675 | 9.8 | N/A | Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access... |
| CVE-2026-9082 | 9.8 | N/A | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affec... |
| CVE-2024-55636 | 9.8 | N/A | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 be... |
| CVE-2024-55637 | 9.8 | N/A | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 be... |
| CVE-2024-55638 | 9.8 | N/A | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before... |
| CVE-2026-9082 | 9.8 | N/A | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affec... |
| CVE-2008-6171 | 9.3 | HIGH | includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to incl... |
| CVE-2016-6211 | 8.8 | N/A | The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a... |
| CVE-2020-13663 | 8.8 | N/A | Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other v... |
| CVE-2020-13664 | 8.8 | N/A | Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site t... |
| CVE-2020-13671 | 8.8 | N/A | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as t... |
| CVE-2021-41164 | 8.2 | N/A | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may af... |
| CVE-2021-41165 | 8.2 | N/A | CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all p... |
| CVE-2016-3162 | 8.1 | N/A | The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a... |
| CVE-2016-3169 | 8.1 | N/A | The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the... |
| CVE-2016-3171 | 8.1 | N/A | Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code vi... |
| CVE-2016-5385 | 8.1 | N/A | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untru... |
| CVE-2017-6381 | 8.1 | N/A | A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htacc... |
| CVE-2017-6926 | 8.1 | N/A | In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are... |
| CVE-2017-6930 | 8.1 | N/A | In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the... |
| CVE-2019-6340 | 8.1 | N/A | Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PH... |
| CVE-2024-55634 | 8.1 | N/A | A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 bef... |
| CVE-2019-6338 | 8.0 | N/A | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This librar... |
| CVE-2022-29248 | 8.0 | N/A | Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not c... |