Filter
AND
-Infinity
0

DrupalXSS

First published (updated )

DrupalXSS

First published (updated )

DrupalXSS

First published (updated )

DrupalXSS

First published (updated )

Oracle REST Data ServicesJQuery Cross-Site Scripting (XSS) Vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

composer/drupal/coreDrupal core - Critical - Cross site scripting - SA-CORE-2025-001

EPSS
0.03%
First published (updated )

Oracle Banking Digital ExperiencePotential XSS vulnerability in jQuery

First published (updated )

composer/drupal/coreXSS

First published (updated )

composer/drupal/coreDrupal core - Moderately critical - Access Bypass - SA-CORE-2022-013

First published (updated )

composer/drupal/coreDrupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not c…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

composer/drupal/coreDrupal core - Moderately critical - Access bypass - SA-CORE-2023-005

First published (updated )

DrupalResponsive and off-canvas menu - Moderately critical - Access bypass - SA-CONTRIB-2024-030

First published (updated )

DrupalPOST File - Critical - Cross Site Scripting, Arbitrary PHP code execution - SA-CONTRIB-2024-060

First published (updated )

DrupalFacets - Critical - Cross Site Scripting - SA-CONTRIB-2024-047

First published (updated )

DrupalDrupal core - Critical - Cross Site Scripting - SA-CORE-2024-005

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Financial Services Analytical Applications InfrastructureCross-site Scripting in CKEditor4

First published (updated )

composer/drupal/coreDrupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004

First published (updated )

composer/drupal/corecore/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) …

First published (updated )

Leighton Whiting Mark CompleteCSRF

First published (updated )

Acquia CommonsThe commons_discussion_views_default_views function in modules/features/commons_discussion/commons_d…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Yandex.MetricaXSS

First published (updated )

Michelle Cox Advanced ForumAdvanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user s…

First published (updated )

Drupal ViewsXSS

First published (updated )

LogintobogganUnspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow …

First published (updated )

Chris Desautels Node Parameter ControlThe Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the config…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Speedtech StormThe Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminv…

First published (updated )

Botcha Spam Prevention ProjectInfoleak

First published (updated )

Thomas Seidl Search ApiCSRF

First published (updated )

David Alkire Email2imageThe email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, wh…

First published (updated )

Mark Burton InsertnodeXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203