Skip to main content
Skip to search
Can we use first and third party cookies and web beacons to
understand our audience, and to tailor promotions you see
?
Yes, please
No, do not track me
Drupal.org home
Discover Drupal
Drupal Core
Drupal CMS
Drupal AI
Case Studies
Drupal for Government
Drupal for Higher Education
Drupal for Nonprofit
Drupal for eCommerce
Drupal for FinTech
Drupal for Healthcare
Drupal for Enterprise
Drupal for Retail
Drupal for Travel & Tourism
Build with Drupal
Download Drupal
Documentation
Getting started
Local Development Guide
Developer Resources
Drupal CMS User Guide
Drupal User Guide
API
Modules
Themes
Recipes
Site Templates
Issue queues
Security Advisories
Partners & Services
Find a Drupal Certified Partner
Become a Drupal Certified Partner
Find a Hosting Provider
Find a Migration Partner
Find Training
Drupal Steward
Community
About the Community
How to Contribute
DrupalCon
Events
News & Blogs
Forum
Slack
Newsletters
Drupal Swag Shop
Support Drupal
The Drupal Association
Donate
Become a Partner
Become a Ripple Maker
Become a Drupal Sustaining Member
Drupal Swag Shop
Get Started
Try Drupal CMS
Try Hosting
Return to content
Search form
Search
Log in
Create account
Security advisories
Show advisories for
only Drupal Core
,
only contributed projects
, or
only
PSAs
SA-CONTRIB-2012-111 - Security Questions - Access Bypass
By
Drupal Security Team
on
11 Jul 2012 at 15:59 UTC
Advisory ID: SA-CONTRIB-2012-111
Project:
Security Questions
(third-party module)
Version: 6.x, 7.x
Date: 2012-July-11
Security risk:
Highly critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-110 - Colorbox Node - Cross Site Scripting (XSS)
By
Drupal Security Team
on
11 Jul 2012 at 15:18 UTC
Advisory ID: SA-CONTRIB-2012-110
Project:
Colorbox Node
(third-party module)
Version: 7.x
Date: 2012-July-11
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-109 - Restrict node page view - Access bypass
By
Drupal Security Team
on
11 Jul 2012 at 15:06 UTC
Advisory ID: SA-CONTRIB-2012-109
Project:
Restrict node page view
(third-party module)
Version: 7.x
Date: 2012-July-11
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-108 - Drag & Drop Gallery - Arbitrary PHP code execution
By
Drupal Security Team
on
11 Jul 2012 at 14:50 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-108
Project:
Drag & Drop Gallery
(third-party module)
Version: 6.x
Date: 2012-July-11
Security risk:
Highly critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting, Access bypass, Cross Site Request Forgery, SQL Injection, Arbitrary PHP code execution
SA-CONTRIB-2012-107 - Search autocomplete - Access bypass
By
Drupal Security Team
on
11 Jul 2012 at 14:34 UTC
Advisory ID: SA-CONTRIB-2012-107
Project:
Search Autocomplete
(third-party module)
Version: 7.x
Date: 2012-July-11
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-106 - Listhandler - Access Bypass
By
Drupal Security Team
on
11 Jul 2012 at 14:31 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-106
Project:
Listhandler
(third-party module)
Version: 6.x
Date: 2012-July-11
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-105 - Hashcash - Cross Site Scripting (XSS)
By
Drupal Security Team
on
27 Jun 2012 at 20:09 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-105
Project:
Hashcash
(third-party module)
Version: 6.x, 7.x
Date: 2012-June-27
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-104 - Privatemsg - Cross Site Scripting (XSS)
By
Drupal Security Team
on
20 Jun 2012 at 17:20 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-104
Project:
Privatemsg
(third-party module)
Version: 7.x
Date: 2012-June-20
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-103 - Global Redirect - Open Redirect
By
Drupal Security Team
on
13 Jun 2012 at 20:47 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-103
Project:
Global Redirect
(third-party module)
Version: 6.x, 7.x
Date: 2012-June-13
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Open Redirect
SA-CONTRIB-2012-102 - Ubercart AJAX Cart - Potential Disclosure of user Session ID
By
Drupal Security Team
on
13 Jun 2012 at 20:41 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-102
Project:
Ubercart AJAX Cart
(third-party module)
Version: 6.x
Date: 2012-June-13
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Information Disclosure
SA-CONTRIB-2012-101 - Protected Node - Access Bypass
By
Drupal Security Team
on
13 Jun 2012 at 18:45 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-101
Project:
Protected node
(third-party module)
Version: 6.x
Date: 2012-June-13
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-100 - SimpleMeta - Cross Site Request Forgery (CSRF)
By
Drupal Security Team
on
13 Jun 2012 at 18:45 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-100
Project:
SimpleMeta
(third-party module)
Version: 6.x
Date: 2012-June-13
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Request Forgery
SA-CONTRIB-2012-099 - Node Hierarchy - Cross Site Request Forgery (CSRF)
By
Drupal Security Team
on
13 Jun 2012 at 18:45 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-099
Project:
Node Hierarchy
(third-party module)
Version: 6.x
Date: 2012-June-13
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Request Forgery
SA-CONTRIB-2012-098 - Janrain Capture - Open Redirect
By
Drupal Security Team
on
13 Jun 2012 at 18:35 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-098
Project:
Janrain Capture
(third-party module)
Version: 6.x, 7.x
Date: 2012-June-13
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Open Redirect
SA-CONTRIB-2012-097 - Protest - Cross Site Scripting (XSS)
By
Drupal Security Team
on
6 Jun 2012 at 20:02 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-097
Project:
Protest
(third-party module)
Version: 6.x, 7.x
Date: 2012-June-06
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-096 - Authoring HTML - Cross Site Scripting (XSS)
By
Drupal Security Team
on
6 Jun 2012 at 19:57 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-096
Project:
Authoring HTML
(third-party module)
Version: 6.x
Date: 2012-June-06
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-095 - Simplenews - Information Disclosure
By
Drupal Security Team
on
6 Jun 2012 at 19:52 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-095
Project:
Simplenews
(third-party module)
Version: 6.x, 7.x
Date: 2012-June-06
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Information Disclosure
SA-CONTRIB-2012-094 - Maestro module - Cross Site Request Forgery (CSRF), Cross Site Scripting (XSS)
By
Drupal Security Team
on
6 Jun 2012 at 19:36 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-094
Project:
Maestro
(third-party module)
Version: 7.x
Date: 2012-June-06
Security risk:
Critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting, Cross Site Request Forgery
SA-CONTRIB-2012-093 - Node Embed - Access Bypass
By
Drupal Security Team
on
6 Jun 2012 at 19:33 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-093
Project:
Node Embed
(third-party module)
Version: 6.x, 7.x
Date: 2012-June-06
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-092 - Organic Groups - Cross Site Scripting (XSS) and Access Bypass
By
Drupal Security Team
on
6 Jun 2012 at 19:26 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-092
Project:
Organic groups
(third-party module)
Version: 6.x
Date: 2012-June-06
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting, Access bypass
SA-CONTRIB-2012-091 - Token Authentication - Access bypass
By
Drupal Security Team
on
6 Jun 2012 at 19:22 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-091
Project:
Tokenauth
(third-party module)
Version: 6.x
Date: 2012-June-06
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-090 - File depot - Session Management Vulnerability
By
Drupal Security Team
on
30 May 2012 at 18:59 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-090
Project:
filedepot
(third-party module)
Version: 6.x
Date: 2012-May-30
Security risk:
Critical
Exploitable from: remote
Vulnerability: Access bypass
SA-CONTRIB-2012-089 - Counter - SQL Injection (unsupported)
By
Drupal Security Team
on
30 May 2012 at 18:37 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-089
Project:
Counter
(third-party module)
Version: 6.x
Date: 2012-May-30
Security risk:
Highly critical
Exploitable from: Remote
Vulnerability: SQL Injection
SA-CONTRIB-2012-088 - Mobile Tools - Cross Site Scripting (XSS)
By
Drupal Security Team
on
30 May 2012 at 18:14 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-088
Project:
Mobile Tools
(third-party module)
Version: 6.x
Date: 2012-May-30
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-087 - Comment Moderation - Cross Site Request Forgery
By
Drupal Security Team
on
30 May 2012 at 18:09 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-087
Project:
Comment Moderation
(third-party module)
Version: 6.x
Date: 2012-May-30
Security risk:
Less Critical
Exploitable from: Remote
Vulnerability: Cross Site Request Forgery
SA-CONTRIB-2012-086 - Amadou - Cross Site Scripting
By
Drupal Security Team
on
30 May 2012 at 17:44 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-086
Project:
Amadou
(third-party theme)
Version: 6.x
Date: 2012-May-30
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-085 - BrowserID - Multiple Vulnerabilities
By
Drupal Security Team
on
23 May 2012 at 17:56 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-085
Project:
BrowserID (Mozilla Persona)
(third-party module)
Version: 7.x
Date: 2012-May-23
Security risk:
Critical
Exploitable from: Remote
Vulnerability: Cross Site Request Forgery (results in Privilege Escalation)
SA-CONTRIB-2012-084 - Search API - Cross Site Scripting (XSS)
By
Drupal Security Team
on
23 May 2012 at 17:09 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-084
Project:
Search API
(third-party module)
Version: 7.x
Date: 2012-May-23
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-083 - Taxonomy List - Cross Site Scripting (XSS)
By
Drupal Security Team
on
23 May 2012 at 16:08 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-083
Project:
Taxonomy List
(third-party module)
Version: 6.x
Date: 2012-May-23
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-082 - Zen - Cross Site Scripting
By
Drupal Security Team
on
16 May 2012 at 20:38 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-082
Project:
Zen
(third-party theme)
Version: 6.x
Date: 2012-May-16
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-081 - Aberdeen - Cross Site Scripting
By
Drupal Security Team
on
16 May 2012 at 20:38 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-081
Project:
Aberdeen
(third-party theme)
Version: 6.x
Date: 2012-May-16
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-080 - Hostmaster (Aegir) - Access Bypass and Cross Site Scripting (XSS)
By
Drupal Security Team
on
16 May 2012 at 16:35 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-080
Project:
Hostmaster (Aegir)
(third-party module)
Version: 6.x
Date: 2012-May-16
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Multiple vulnerabilities
SA-CONTRIB-2012-079 - Post Affiliate Pro - Cross Site Scripting (XSS) and Access Bypass - Unsupported
By
Drupal Security Team
on
16 May 2012 at 16:21 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-079
Project:
Post Affiliate Pro
(third-party module)
Version: 6.x
Date: 2012-May-16
Security risk:
Critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting, Access bypass
SA-CONTRIB-2012-078 - Smart Breadcrumb - Cross Site Scripting (XSS)
By
Drupal Security Team
on
16 May 2012 at 15:30 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-078
Project:
Smart Breadcrumb
(third-party module)
Version: 6.x
Date: 2012-May-16
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-077 - Advertisement - Cross Site Scripting & Information Disclosure
By
Drupal Security Team
on
16 May 2012 at 15:16 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-077
Project:
Advertisement
(third-party module)
Version: 6.x
Date: 2012-May-16
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting, Information Disclosure, Multiple vulnerabilities
SA-CONTRIB-2012-076 - Ubercart Product Keys Access Bypass
By
Drupal Security Team
on
16 May 2012 at 15:07 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-076
Project:
Ubercart Product Keys
(third-party module)
Version: 6.x
Date: 2012-May-16
Security risk:
Moderately Critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-075 - Take Control - Cross Site Request Forgery (CSRF)
By
Drupal Security Team
on
9 May 2012 at 16:40 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-075
Project:
Take Control
(third-party module)
Version: 6.x
Date: 2012-May-09
Security risk:
Critical
Exploitable from: Remote
Vulnerability: Cross Site Request Forgery
SA-CONTRIB-2012-074 - Contact Forms - Access Bypass
By
Drupal Security Team
on
9 May 2012 at 16:36 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-074
Project:
Contact Forms
(third-party module)
Version: 7.x
Date: 2012-May-09
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-073 - Glossary - Cross-Site Scripting (XSS)
By
Drupal Security Team
on
9 May 2012 at 16:24 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-073
Project:
Glossary
(third-party module)
Version: 6.x
Date: 2012-May-09
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-072 - cctags - Cross Site Scripting (XSS)
By
Drupal Security Team
on
2 May 2012 at 19:36 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-072
Project:
cctags
(third-party module)
Version: 6.x, 7.x
Date: 2012-May-02
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CORE-2012-002 - Drupal core multiple vulnerabilities
By
Drupal Security Team
on
2 May 2012 at 15:17 UTC
Advisory ID: DRUPAL-SA-CORE-2012-002
Project:
Drupal core
Version: 7.x
Date: 2012-May-2
Security risk:
Critical
Exploitable from: Remote
Vulnerability: Denial of Service, Access bypass, Unvalidated form redirect
SA-CONTRIB-2012-071 - Glossify - Cross Site Scripting (XSS) - Unsupported
By
Drupal Security Team
on
2 May 2012 at 14:34 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-071
Project:
Glossify Internal Links Auto SEO
(third-party module)
Version: 6.x
Date: 2012-May-02
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-070 - Taxonomy Grid : Catalog - Cross Site Scripting (XSS) - Unsupported
By
Drupal Security Team
on
2 May 2012 at 14:33 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-070
Project:
Taxonomy Grid : Catalog
(third-party module)
Version: 6.x
Date: 2012-May-02
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
SA-CONTRIB-2012-069 - Addressbook - Multiple vulnerabilities - Unsupported
By
Drupal Security Team
on
2 May 2012 at 14:31 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-069
Project:
Addressbook
(third-party module)
Version: 6.x
Date: 2012-May-02
Security risk:
Highly critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting, Cross Site Request Forgery, SQL Injection
SA-CONTRIB-2012-068 - Node Gallery - Cross Site Request Forgery (CSRF) - Unsupported
By
Drupal Security Team
on
2 May 2012 at 14:09 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-068
Project:
Node Gallery
(third-party module)
Version: 6.x
Date: 2012-May-02
Security risk:
Less critical
Exploitable from: Remote
Vulnerability: Cross Site Request Forgery
SA-CONTRIB-2012-067 - Linkit - Access bypass
By
Drupal Security Team
on
25 Apr 2012 at 19:29 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-067
Project:
Linkit
(third-party module)
Version: 7.x
Date: 2012-April-25
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-066 - Spaces and Spaces OG - Access Bypass
By
Drupal Security Team
on
25 Apr 2012 at 19:26 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-066
Project:
Spaces
(third-party module)
Version: 6.x
Date: 2012-April-25
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Access bypass
SA-CONTRIB-2012-065 - Sitedoc - Information disclosure
By
Drupal Security Team
on
25 Apr 2012 at 19:14 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-065
Project:
Site Documentation
(third-party module)
Version: 6.x
Date: 2012-April-25
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Information Disclosure
SA-CONTRIB-2012-064 - Ubercart - Multiple vulnerabilities
By
Drupal Security Team
on
25 Apr 2012 at 19:04 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-064
Project:
Ubercart
(third-party module)
Version: 6.x, 7.x
Date: 2012-April-25
Security risk:
Moderately critical
Exploitable from: Varies (Local & Remote)
Vulnerability: Cross Site Scripting, Arbitrary PHP code execution, Multiple vulnerabilities
SA-CONTRIB-2012-063 - RealName - Cross Site Scripting (XSS)
By
Drupal Security Team
on
25 Apr 2012 at 18:52 UTC
Advisory ID: DRUPAL-SA-CONTRIB-2012-063
Project:
RealName
(third-party module)
Version: 6.x
Date: 2012-April-25
Security risk:
Moderately critical
Exploitable from: Remote
Vulnerability: Cross Site Scripting
Pages
« first
‹ previous
…
28
29
30
31
32
33
34
35
36
…
next ›
last »
Subscribe with RSS