Loading HuntDB...

Drupal

75 Products 122 CVEs

CVE Severity Distribution (All Time)

Critical
13
High
17
Medium
45
Low
3

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 68 CVEs
Last Year 78 CVEs

Recent CVEs

View all
CVE-2024-13312 MEDIUM 5 months, 1 week ago

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 1…

CVE-2024-13309 MEDIUM 5 months, 1 week ago

Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…

CVE-2024-13308 LOW 5 months, 1 week ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Sc…

CVE-2024-13305 MEDIUM 5 months, 1 week ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scri…

CVE-2024-13304 MEDIUM 5 months, 1 week ago

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before…

CVE-2024-13303 MEDIUM 5 months, 1 week ago

Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.…

CVE-2024-13302 MEDIUM 5 months, 1 week ago

Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2…

CVE-2024-13301 MEDIUM 5 months, 1 week ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – …

CVE-2024-13298 MEDIUM 5 months, 1 week ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Script…

CVE-2024-13297 MEDIUM 5 months, 1 week ago

Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.