Loading...
Loading...
The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.
October 19, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-5597
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.