Show advisories for only Drupal core, only PSAs, or all security advisories

Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by community members.

SA-CONTRIB-2011-048 - Certificate Login SQL Injection

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-048
  • Project: Certificate Login (third-party module)
  • Version: 5.x, 6.x
  • Date: 2011-October-12
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

SA-CONTRIB-2011-047 - OG Features access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-047
  • Project: OG Features (third-party module)
  • Version: 6.x
  • Date: 2011-October-05
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2011-046 - Echo - Multiple Vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-046
  • Project: Echo (third-party module)
  • Version: 6.x, 7.x, 8.x
  • Date: 2011-October-05
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

SA-CONTRIB-2011-045 - Rate module Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-045
  • Project: Rate (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-October-05
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting (XSS)

SA-CONTRIB-2011-044 - Homebox for Organic Groups Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-044
  • Project: Homebox (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-October-05
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting (XSS)

SA-CONTRIB-2011-043 - Petition Node - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-043
  • Project: petition_node (third-party module)
  • Version: 6.x
  • Date: 2011-October-05
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-042 Views Bulk Operations - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-042
  • Project: Views Bulk Operations (VBO) (third-party module)
  • Version: 6.x
  • Date: 2011-September-21
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-041 - Hostmaster (Aegir) - Cross Site Scripting

  • Advisory ID: SA-CONTRIB-2011-041
  • Project: Hostmaster (Aegir) (third-party module)
  • Version: 6.x
  • Date: 2011-September-21
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-040 Author Pane access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-040
  • Project: Author Pane (third-party module)
  • Version: 6.x
  • Date: 2011-September-7
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2011-039 - Bot Alarm - Multiple vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-039
  • Project: Bot Alarm (third-party module)
  • Version: 6.x
  • Date: 2011-August-31
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery

Pages

Subscribe with RSS Subscribe to Security advisories for contributed projects