drupal/core
Packagist118 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting drupal/corepage 1 of 3
- CVE-2011-2687HIGHCVSS v2 7.5EG 7.5fixed in 7.32011-07-27
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
- CVE-2011-2714MEDIUMCVSS 6.1EG 6.12020-01-14
vulnerable: 6.20
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
- CVE-2011-2715CRITICALCVSS 9.8EG 9.82020-01-14
vulnerable: 6.20
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
- CVE-2016-3162HIGHCVSS 8.1EG 8.1fixed in 7.43 or 8.0.4, by version range2016-04-12
vulnerable: 8.0.0 ... 8.0.3 (19 versions)
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to cre…
- CVE-2016-3163HIGHCVSS 7.5EG 7.5fixed in 7.43 or 6.38, by version range2016-04-12
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
- CVE-2016-3164HIGHCVSS 7.4EG 7.4fixed in 8.0.4, 7.43 or 6.38, by version range2016-04-12
vulnerable: 8.0.0 ... 8.0.3 (19 versions)
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
- CVE-2016-3165HIGHCVSS 7.5EG 7.5fixed in 6.382016-04-12
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set …
- CVE-2016-3166MEDIUMCVSS 5.9EG 5.9fixed in 6.382016-04-12
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a…
- CVE-2016-3167HIGHCVSS 7.4EG 7.4fixed in 6.382016-04-12
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in t…
- CVE-2016-3168MEDIUMCVSS 6.4EG 6.4fixed in 6.38 or 7.43, by version range2016-04-12
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected…
- CVE-2016-3169HIGHCVSS 8.1EG 8.1fixed in 6.38 or 7.43, by version range2016-04-12
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the arra…
- CVE-2016-3170MEDIUMCVSS 5.3EG 5.3fixed in 7.43 or 8.0.4, by version range2016-04-12
vulnerable: 8.0.0 ... 8.0.3 (19 versions)
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email addres…
- CVE-2016-3171HIGHCVSS 8.1EG 8.1fixed in 6.382016-04-12
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
- CVE-2016-5385HIGHCVSS 8.1EG 8.4fixed in 8.1.72016-07-19
vulnerable: 8.0.0 ... 8.1.6 (32 versions)
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remo…
- CVE-2016-6211HIGHCVSS 8.8EG 8.8fixed in 7.442016-09-09
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
- CVE-2016-6212MEDIUMCVSS 5.3EG 5.3fixed in 8.1.32016-09-09
vulnerable: 8.0.0 ... 8.1.2 (28 versions)
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecifie…
- CVE-2016-7570MEDIUMCVSS 4.3EG 4.3fixed in 8.1.102016-10-03
vulnerable: 8.0.0 ... 8.1.9 (20 versions)
Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.
- CVE-2016-7571MEDIUMCVSS 6.1EG 6.1fixed in 8.1.102016-10-03
vulnerable: 8.0.0 ... 8.1.9 (35 versions)
Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.
- CVE-2016-7572MEDIUMCVSS 4.3EG 4.3fixed in 8.1.102016-10-03
vulnerable: 8.0.0 ... 8.1.9 (35 versions)
The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecif…
- CVE-2016-9449MEDIUMCVSS 4.3EG 4.3fixed in 7.52 or 8.2.3, by version range2016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
- CVE-2016-9450HIGHCVSS 7.5EG 7.5fixed in 8.2.32016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
- CVE-2016-9451MEDIUMCVSS 6.8EG 6.8fixed in 7.52 or 8.2.3, by version range2016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
- CVE-2016-9452MEDIUMCVSS 6.5EG 6.5fixed in 8.2.32016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.
- CVE-2017-6377HIGHCVSS 7.5EG 7.5fixed in 8.2.72017-03-16
vulnerable: 8.2.0 ... 8.2.6 (7 versions)
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
- CVE-2017-6379HIGHCVSS 7.5EG 7.5fixed in 8.2.72017-03-16
vulnerable: 8.2.0 ... 8.2.6 (7 versions)
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
- CVE-2017-6381HIGHCVSS 8.1EG 8.1fixed in 8.2.72017-03-16
vulnerable: 8.0.0 ... 8.2.6 (48 versions)
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development de…
- CVE-2017-6919HIGHCVSS 7.5EG 7.5fixed in 8.2.8 or 8.3.1, by version range2017-04-20
vulnerable: 8.3.0
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
- CVE-2017-6920CRITICALCVSS 9.8EG 9.8fixed in 8.3.42018-08-06
vulnerable: 8.0.0 ... 8.3.3 (58 versions)
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
- CVE-2017-6921MEDIUMCVSS 5.9EG 5.9fixed in 8.3.42019-01-15
vulnerable: 8.0.0 ... 8.3.3 (58 versions)
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is en…
- CVE-2017-6922MEDIUMCVSS 6.5EG 6.5fixed in 7.56 or 8.3.4, by version range2019-01-22
vulnerable: 8.0.0 ... 8.3.3 (58 versions)
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded …
- CVE-2017-6923MEDIUMCVSS 6.5EG 6.5fixed in 8.3.72019-01-22
vulnerable: 8.0.0 ... 8.3.6 (61 versions)
In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax…
- CVE-2017-6924HIGHCVSS 7.4EG 7.4fixed in 8.3.72019-01-15
vulnerable: 8.0.0 ... 8.3.6 (61 versions)
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that …
- CVE-2017-6925CRITICALCVSS 9.8EG 9.8fixed in 8.3.72019-01-15
vulnerable: 8.0.0 ... 8.3.6 (61 versions)
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs…
- CVE-2017-6926HIGHCVSS 8.1EG 8.1fixed in 8.4.5 or 7.57, by version range2018-03-01
vulnerable: 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.4
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by t…
- CVE-2017-6927MEDIUMCVSS 6.1EG 6.1fixed in 8.4.5 or 7.57, by version range2018-03-01
vulnerable: 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.4
Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically g…
- CVE-2017-6928MEDIUMCVSS 5.3EG 5.3fixed in 7.572018-03-01
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which on…
- CVE-2017-6929MEDIUMCVSS 6.1EG 6.1fixed in 7.57 or 8.4.0, by version range2018-03-01
vulnerable: 8.0.0 ... 8.4.0-rc2 (68 versions)
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulne…
- CVE-2017-6930HIGHCVSS 8.1EG 8.1fixed in 8.4.52018-03-01
vulnerable: 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.4
In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that d…
- CVE-2017-6931MEDIUMCVSS 6.5EG 6.5fixed in 8.4.52018-03-01
vulnerable: 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.4
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a cu…
- CVE-2017-6932MEDIUMCVSS 4.7EG 4.7fixed in 7.572018-03-01
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacke…
- CVE-2018-7600CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 8.3.9, 8.4.6, 8.5.1 or 7.58, by version range2018-03-29
vulnerable: 8.5.0
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
- CVE-2018-7602CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 8.4.8, 8.5.3 or 7.59, by version range2018-07-19
vulnerable: 8.5.0 ... 8.5.2 (6 versions)
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vu…
- CVE-2018-9861MEDIUMCVSS 6.1EG 6.1fixed in 8.4.7 or 8.5.2, by version range2018-04-19
vulnerable: 8.0.0 ... 8.4.6 (75 versions)
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote a…
- CVE-2019-10909MEDIUMCVSS 5.4EG 5.4fixed in 8.5.15 or 8.6.15, by version range2019-05-16
vulnerable: 8.6.0 ... 8.6.9 (15 versions)
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundl…
- CVE-2019-11358CRITICALCVSS 6.1EG 9.0fixed in 8.5.15 or 8.6.15, by version range2019-04-20
vulnerable: 8.0.0 ... 8.6.9 (95 versions)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could e…
- CVE-2019-11831CRITICALCVSS 9.8EG 9.8fixed in 8.6.16, 8.7.1 or 7.67.0, by version range2019-05-09
vulnerable: 8.7.0
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a pha…
- CVE-2019-6338HIGHCVSS 8.0EG 8.0fixed in 8.5.9 or 8.6.6, by version range2019-01-22
vulnerable: 8.0.0 ... 8.6.5 (80 versions)
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refe…
- CVE-2019-6339CRITICALCVSS 9.8EG 9.8fixed in 8.5.9, 8.6.6 or 7.62.0, by version range2019-01-22
vulnerable: 8.6.0 ... 8.6.5 (6 versions)
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some …
- CVE-2019-6340CRITICALCVSS 8.1EG 9.0⚠ KEVfixed in 8.5.11, 8.6.10 or 7.62.0, by version range2019-02-21
vulnerable: 8.0.0 ... 8.5.9 (76 versions)
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the f…
- CVE-2019-6341MEDIUMCVSS 5.4EG 5.4fixed in 8.5.14, 8.6.13 or 7.65.0, by version range2019-03-26
vulnerable: 8.6.0 ... 8.6.9 (13 versions)
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scrip…
Check whether drupal/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for drupal/core CVEs against the assets you own.
Book a Demo →