| Drupal | Number Of NVD | 254 | CRITICAL | 12 | HIGH | 57 | MEDIUM | 162 | LOW | 23 |
| URL | https://www.drupal.org/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Drupal is an open source Content Management System (CMS). Compared to WordPress and Joomla, it is said to be faster in displaying pages. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://www.drupal.org/download | ||
| 2 | https://www.drupal.org/project/drupal/releases | ||
| 3 | https://github.com/drupal/drupal | ||
| 4 | https://www.drupal.org/about/drupal6-eol | ||
| 5 | https://www.drupal.org/blog/drupal-7-8-and-9 |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 151 | Drupal 10 | 10.6.0-beta1 | Nov. 25, 2025 | Dec. 15, 2022 | 1 | 1 | 5 | 1 | |||
| 152 | Drupal 9 | 9.5.11 | Sept. 20, 2023 | June 3, 2020 | 3 | 20 | 23 | 1 | |||
| 153 | Drupal 8 | 8.9.20 | Nov. 17, 2021 | June 3, 2020 | Nov. 30, 2021 | 11 | 29 | 39 | 1 | ||
| 154 | Drupal 7 | 7.103 | Dec. 4, 2024 | Jan. 5, 2011 | Nov. 30, 2021 | 4 | 18 | 68 | 8 | ||
| 155 | Drupal 6 | 6.38 | Feb. 24, 2016 | Feb. 13, 2008 | Feb. 24, 2016 | 2 | 10 | 61 | 14 | ||
| 156 | Drupal 5 | 5.23 | Aug. 11, 2010 | Jan. 15, 2007 | Jan. 6, 2011 | 1 | 5 | 43 | 8 | ||
| 157 | Drupal 4 | 4.7.11 | Jan. 10, 2008 | June 15, 2002 | Jan. 1, 1900 | 1 | 7 | 37 | 7 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 151 |
- 4.3 |
MEDIUM | The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of othe… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2013-0246 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:47 2013-07-17 |
Show | GitHub Exploit DB Packet Storm | ||||
| 152 |
- 2.1 |
LOW | The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows rem… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2013-0245 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:47 2013-07-17 |
Show | GitHub Exploit DB Packet Storm | ||||
| 153 |
- 5.0 |
MEDIUM | The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests. |
CWE-399
Resource Management Errors |
CVE-2013-0316 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:47 2013-03-28 |
Show | GitHub Exploit DB Packet Storm | ||||
| 154 |
- 6.0 |
MEDIUM | The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file nam… |
CWE-20
Improper Input Validation |
CVE-2012-5653 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:45 2013-01-3 |
Show | GitHub Exploit DB Packet Storm | ||||
| 155 |
- 5.0 |
MEDIUM | Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. |
CWE-200
Information Exposure |
CVE-2012-5652 |
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru… |
2024-11-21 10:45 2013-01-3 |
Show | GitHub Exploit DB Packet Storm | ||||
| 156 |
- 5.0 |
MEDIUM | Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-5651 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:45 2013-01-3 |
Show | GitHub Exploit DB Packet Storm | ||||
| 157 |
- 5.0 |
MEDIUM | The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-4554 |
cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal:drupal:7.7:* cpe:2.3:a:drupal:dru… |
2024-11-21 10:43 2012-11-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 158 |
- 6.8 |
MEDIUM | Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient con… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-4553 |
cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal:drupal:7.7:* cpe:2.3:a:drupal:dru… |
2024-11-21 10:43 2012-11-11 |
Show | GitHub Exploit DB Packet Storm | ||||
| 159 |
- 4.0 |
MEDIUM | Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overvie… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-2153 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:38 2012-10-1 |
Show | GitHub Exploit DB Packet Storm | ||||
| 160 |
- 5.0 |
MEDIUM | The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-1591 |
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal… |
2024-11-21 10:37 2012-10-1 |
Show | GitHub Exploit DB Packet Storm |