Vulnerabilities (CVE)

Total 398612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-13310 1 Git Utilities Project 1 Git Utilities 2026-06-17 N/A 6.5 MEDIUM
Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.
CVE-2024-13309 1 Login Disable Project 1 Login Disable 2026-06-17 N/A 5.4 MEDIUM
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.
CVE-2024-13308 1 Browser Back Button Project 1 Browser Back Button 2026-06-17 N/A 3.8 LOW
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.
CVE-2024-13307 2026-06-17 N/A 5.3 MEDIUM
The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites' functions in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary attachments, and add or remove favorite property listings for any user.
CVE-2024-13306 1 Wpgooglemap 1 Wp Google Map 2026-06-17 N/A 4.3 MEDIUM
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13305 1 Imagexmedia 1 Entity Form Steps 2026-06-17 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.
CVE-2024-13304 1 Matthiasmullie 1 Minify Js 2026-06-17 N/A 4.5 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.
CVE-2024-13303 1 Download All Files Project 1 Download All Files 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.
CVE-2024-13302 1 Ciandt 1 Pages Restriction Access 2026-06-17 N/A 5.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.
CVE-2024-13301 1 Miniorange 1 Oauth \& Openid Connect Single Sign-on 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0, from 4.0.0 before 4.0.19.
CVE-2024-13300 1 Print Anything Project 1 Print Anything 2026-06-17 N/A 6.6 MEDIUM
Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*.
CVE-2024-13299 1 Boozallen 1 Megamenu Framework 2026-06-17 N/A 6.6 MEDIUM
Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*.
CVE-2024-13298 1 Kleegroup 1 Tarte Au Citron 2026-06-17 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5.
CVE-2024-13297 1 Eloqua Project 1 Eloqua 2026-06-17 N/A 6.6 MEDIUM
Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.
CVE-2024-13296 1 Mailjet 1 Mailjet 2026-06-17 N/A 6.6 MEDIUM
Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.
CVE-2024-13295 1 Node Export Project 1 Node Export 2026-06-17 N/A 6.6 MEDIUM
Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.
CVE-2024-13294 1 Post File Project 1 Post File 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal POST File allows Cross-Site Scripting (XSS).This issue affects POST File: from 0.0.0 before 1.0.2.
CVE-2024-13293 1 Post File Project 1 Post File 2026-06-17 N/A 3.1 LOW
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.
CVE-2024-13292 1 Tooltip Project 1 Tooltip 2026-06-17 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip allows Cross-Site Scripting (XSS).This issue affects Tooltip: from 0.0.0 before 1.1.2.
CVE-2024-13291 1 Basic Http Authentication Project 1 Basic Http Authentication 2026-06-17 N/A 7.3 HIGH
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.