Drupal

Drupal

266 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 26.04.2023 14:15:09
  • Zuletzt bearbeitet 03.02.2025 19:15:08

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content general...

  • EPSS 0.31%
  • Veröffentlicht 26.04.2023 14:15:09
  • Zuletzt bearbeitet 03.02.2025 19:15:09

In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system. Access to a non-public file is checked only if it i...

  • EPSS 1.57%
  • Veröffentlicht 28.09.2022 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:54

Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `in...

  • EPSS 0.74%
  • Veröffentlicht 10.06.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:46

Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on ...

  • EPSS 0.95%
  • Veröffentlicht 10.06.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:46

Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we ...

  • EPSS 0.45%
  • Veröffentlicht 25.05.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:48

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the ...

  • EPSS 0.67%
  • Veröffentlicht 21.03.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 06:51:04

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There ar...

  • EPSS 0.51%
  • Veröffentlicht 16.03.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:50:57

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a ...

  • EPSS 0.72%
  • Veröffentlicht 16.03.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 06:50:57

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to in...

  • EPSS 0.25%
  • Veröffentlicht 17.02.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:55

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the Qui...