VulnSea

drupal vulnerabilities

CVEs whose affected-version data names the drupal package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2021-41164High· 8.2
4y ago

CKEditor4 is an open source WYSIWYG HTML editor

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malf…

Twilightckeditor · ckeditorEPSS 1.3%via NVD
CVE-2021-41184Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0.…

Twilightjqueryui · jquery_uiEPSS 41%via NVD
CVE-2021-41183Medium· 6.5
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI …

Sunlitjqueryui · jquery_uiEPSS 8.5%via NVD
CVE-2021-41182Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…

Twilightjqueryui · jquery_uiEPSS 39%via NVD
CVE-2020-9281Medium· 6.1
6y ago

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

Sunlitckeditor · ckeditorEPSS 4.3%via NVD
CVE-2018-7602Critical· 9.8CISA KEVPoC
8y ago

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This …

Hadaldrupal · drupalEPSS 99%via NVD
drupal vulnerabilities (CVEs) · VulnSea