Drupal

Drupal

271 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 25.05.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:48

Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the ...

  • EPSS 0.73%
  • Veröffentlicht 21.03.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 06:51:04

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There ar...

  • EPSS 0.51%
  • Veröffentlicht 16.03.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:50:57

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a ...

  • EPSS 0.72%
  • Veröffentlicht 16.03.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 06:50:57

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to in...

  • EPSS 0.25%
  • Veröffentlicht 17.02.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:55

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the Qui...

  • EPSS 0.45%
  • Veröffentlicht 16.02.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 06:51:55

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but...

  • EPSS 0.62%
  • Veröffentlicht 11.02.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:01:43

Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior...

  • EPSS 0.57%
  • Veröffentlicht 11.02.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:01:43

Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

  • EPSS 0.43%
  • Veröffentlicht 11.02.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:01:43

Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8....

  • EPSS 0.77%
  • Veröffentlicht 11.02.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 05:01:44

Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x...