drupal/core
Packagist108 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting drupal/corepage 1 of 3
- CVE-2011-2687NONECVSS 0.0EG 0.0✓ Fixed in 7.32011-07-27
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
- CVE-2011-2714MEDIUMCVSS 6.1EG 6.12020-01-14
vulnerable: 6.20
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
- CVE-2011-2715CRITICALCVSS 9.8EG 9.82020-01-14
vulnerable: 6.20
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
- CVE-2016-3162HIGHCVSS 8.1EG 8.1✓ Fixed in 8.0.42016-04-12
vulnerable: 8.0.0 ... 8.0.3 (19 versions)
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to cre…
- CVE-2016-3163HIGHCVSS 7.5EG 7.5✓ Fixed in 6.382016-04-12
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
- CVE-2016-3164HIGHCVSS 7.4EG 7.4✓ Fixed in 6.382016-04-12
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
- CVE-2016-3165HIGHCVSS 7.5EG 7.5✓ Fixed in 6.382016-04-12
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set …
- CVE-2016-3166MEDIUMCVSS 5.9EG 5.9✓ Fixed in 6.382016-04-12
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a…
- CVE-2016-3167HIGHCVSS 7.4EG 7.4✓ Fixed in 6.382016-04-12
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in t…
- CVE-2016-3168MEDIUMCVSS 6.4EG 6.4✓ Fixed in 7.432016-04-12
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected…
- CVE-2016-3169HIGHCVSS 8.1EG 8.1✓ Fixed in 7.432016-04-12
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the arra…
- CVE-2016-3170MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.0.42016-04-12
vulnerable: 8.0.0 ... 8.0.3 (19 versions)
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email addres…
- CVE-2016-3171HIGHCVSS 8.1EG 8.1✓ Fixed in 6.382016-04-12
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
- CVE-2016-5385HIGHCVSS 8.1EG 8.1✓ Fixed in 8.1.72016-07-19
vulnerable: 8.0.0 ... 8.1.6 (32 versions)
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remo…
- CVE-2016-6211HIGHCVSS 8.8EG 8.8✓ Fixed in 7.442016-09-09
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
- CVE-2016-6212MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.1.32016-09-09
vulnerable: 8.0.0 ... 8.1.2 (28 versions)
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecifie…
- CVE-2016-7570MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.1.102016-10-03
vulnerable: 8.0.0 ... 8.1.9 (20 versions)
Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.
- CVE-2016-7571MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.1.102016-10-03
vulnerable: 8.0.0 ... 8.1.9 (35 versions)
Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.
- CVE-2016-7572MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.1.102016-10-03
vulnerable: 8.0.0 ... 8.1.9 (35 versions)
The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecif…
- CVE-2016-9449MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.2.32016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
- CVE-2016-9450HIGHCVSS 7.5EG 7.5✓ Fixed in 8.2.32016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
- CVE-2016-9451MEDIUMCVSS 6.8EG 6.8✓ Fixed in 8.2.32016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
- CVE-2016-9452MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.2.32016-11-25
vulnerable: 8.0.0 ... 8.2.2 (44 versions)
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.
- CVE-2017-6377HIGHCVSS 7.5EG 7.5✓ Fixed in 8.2.72017-03-16
vulnerable: 8.2.0 ... 8.2.6 (7 versions)
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
- CVE-2017-6379HIGHCVSS 7.5EG 7.5✓ Fixed in 8.2.72017-03-16
vulnerable: 8.2.0 ... 8.2.6 (7 versions)
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
- CVE-2017-6381HIGHCVSS 8.1EG 8.1✓ Fixed in 8.2.72017-03-16
vulnerable: 8.0.0 ... 8.2.6 (48 versions)
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development de…
- CVE-2017-6919HIGHCVSS 7.5EG 7.5✓ Fixed in 8.3.12017-04-20
vulnerable: 8.3.0
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
- CVE-2017-6920CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.3.42018-08-06
vulnerable: 8.0.0 ... 8.3.3 (58 versions)
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
- CVE-2017-6921MEDIUMCVSS 5.9EG 5.9✓ Fixed in 8.3.42019-01-15
vulnerable: 8.0.0 ... 8.3.3 (58 versions)
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is en…
- CVE-2017-6922MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.3.42019-01-22
vulnerable: 8.0.0 ... 8.3.3 (58 versions)
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded …
- CVE-2017-6923MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.3.72019-01-22
vulnerable: 8.0.0 ... 8.3.6 (61 versions)
In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax…
- CVE-2017-6924HIGHCVSS 7.4EG 7.4✓ Fixed in 8.3.72019-01-15
vulnerable: 8.0.0 ... 8.3.6 (61 versions)
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that …
- CVE-2017-6925CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.3.72019-01-15
vulnerable: 8.0.0 ... 8.3.6 (61 versions)
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs…
- CVE-2017-6926HIGHCVSS 8.1EG 8.1✓ Fixed in 7.572018-03-01
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by t…
- CVE-2017-6927MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.572018-03-01
Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically g…
- CVE-2017-6928MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.572018-03-01
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which on…
- CVE-2017-6929MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.4.02018-03-01
vulnerable: 8.0.0 ... 8.4.0-rc2 (68 versions)
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulne…
- CVE-2017-6930HIGHCVSS 8.1EG 8.1✓ Fixed in 8.4.52018-03-01
vulnerable: 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.4
In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that d…
- CVE-2017-6931MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.4.52018-03-01
vulnerable: 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.4
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a cu…
- CVE-2017-6932MEDIUMCVSS 4.7EG 4.7✓ Fixed in 7.572018-03-01
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacke…
- CVE-2018-7600CRITICALCVSS 9.8EG 9.8⚠ KEV✓ Fixed in 8.5.12018-03-29
vulnerable: 8.5.0
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
- CVE-2018-7602CRITICALCVSS 9.8EG 9.8⚠ KEV✓ Fixed in 8.5.32018-07-19
vulnerable: 8.5.0 ... 8.5.2 (6 versions)
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vu…
- CVE-2018-9861MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.4.72018-04-19
vulnerable: 8.0.0 ... 8.4.6 (75 versions)
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote a…
- CVE-2019-10909MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.152019-05-16
vulnerable: 8.6.0 ... 8.6.9 (15 versions)
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundl…
- CVE-2019-11358MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.6.152019-04-20
vulnerable: 8.0.0 ... 8.6.9 (95 versions)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could e…
- CVE-2019-11831CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.7.12019-05-09
vulnerable: 8.7.0
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a pha…
- CVE-2019-6338HIGHCVSS 8.0EG 8.0✓ Fixed in 8.6.62019-01-22
vulnerable: 8.0.0 ... 8.6.5 (80 versions)
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refe…
- CVE-2019-6339CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.6.62019-01-22
vulnerable: 8.6.0 ... 8.6.5 (6 versions)
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some …
- CVE-2019-6340HIGHCVSS 8.1EG 9.0⚠ KEV✓ Fixed in 8.5.112019-02-21
vulnerable: 8.0.0 ... 8.5.9 (76 versions)
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the f…
- CVE-2019-6341MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.132019-03-26
vulnerable: 8.6.0 ... 8.6.9 (13 versions)
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scrip…
Check whether drupal/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for drupal/core CVEs against the assets you own.
Start Free Scan →