Show advisories for only Drupal core, only PSAs, or all security advisories

Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by community members.

SA-CONTRIB-2012-139 - PDFThumb OS Injection

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-139
  • Project: PDFThumb (third-party module)
  • Version: 7.x
  • Date: 2012-September-12
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: OS Injection

SA-CONTRIB-2012-138 - Exposed Filter Data - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-138
  • Project: Exposed Filter Data (third-party module)
  • Version: 6.x
  • Date: 2012-September-05
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2012-137 - Heartbeat - Cross Site Request Forgery (CSRF) in heartbeat_comments

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-137
  • Project: Heartbeat (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-September-5
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery

SA-CONTRIB-2012-136 - Apache Solr Search Autocomplete - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-136
  • Project: Apache Solr Autocomplete (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-August-29
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2012-135 - CAPTCHA - Insufficient anti-automation prevention

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-135
  • Project: CAPTCHA (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2012-134 - Views - Privilege Escalation

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-134
  • Project: Views (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Privilege escalation

SA-CONTRIB-2012-133 - Taxonomy Image - Cross Site Scripting (XSS) & Arbitrary PHP code execution

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-133
  • Project: Taxonomy Image (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Arbitrary PHP code execution

SA-CONTRIB-2012-132 - Announcements - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-132
  • Project: Announcements (third-party module)
  • Version: 6.x
  • Date: 2012-August-29
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2012-131 - Email Field - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-131
  • Project: Email Field (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-August-29
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2012-130 - Jstool - Multiple Vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-130
  • Project: Javascript Tool (third-party module)
  • Version: 7.x
  • Date: 2012-August-29
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

Pages

Subscribe with RSS Subscribe to Security advisories for contributed projects