| Bug | Description |
|---|
| CVE-2008-3661 | Drupal, probably 5.10 and 6.4, does not set the secure flag for the ... |
| CVE-2008-4789 | The validation functionality in the core upload module in Drupal 6.x ... |
| CVE-2008-4791 | The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might ... |
| CVE-2008-4792 | The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 ... |
| CVE-2008-4793 | The node module API in Drupal 5.x before 5.11 allows remote attackers ... |
| CVE-2008-6170 | Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and ... |
| CVE-2008-6171 | includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, ... |
| CVE-2008-6532 | Multiple cross-site request forgery (CSRF) vulnerabilities in the ... |
| CVE-2008-6533 | Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related ... |
| CVE-2009-0382 | Unspecified vulnerability in Internationalization (i18n) Translation ... |
| CVE-2009-1575 | Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and ... |
| CVE-2009-1576 | Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before ... |
| CVE-2009-1844 | Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x ... |
| CVE-2009-2372 | Drupal 6.x before 6.13 does not prevent users from modifying user ... |
| CVE-2009-2373 | Cross-site scripting (XSS) vulnerability in the Forum module in Drupal ... |
| CVE-2009-2374 | Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ... |
| CVE-2009-4369 | Cross-site scripting (XSS) vulnerability in the Contact module ... |
| CVE-2009-4370 | Cross-site scripting (XSS) vulnerability in the Menu module ... |
| CVE-2009-4371 | Cross-site scripting (XSS) vulnerability in the Locale module ... |
| CVE-2010-2250 | Installation cross site scripting |
| CVE-2010-2471 | Open redirection |
| CVE-2010-2472 | Locale module cross site scripting |
| CVE-2010-2473 | Blocked user session regeneration |
| CVE-2010-3091 | The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ... |
| CVE-2010-3092 | The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does ... |
| CVE-2010-3093 | The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 ... |
| CVE-2010-3094 | Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x ... |
| CVE-2010-3685 | The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ... |
| CVE-2010-3686 | The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ... |
| CVE-2011-2687 | Drupal 7.x before 7.3 allows remote attackers to bypass intended ... |
| CVE-2012-0827 | |
| TEMP-0000000-FC3A86 | unspecified multiple Drupal vulnerabilies, likely some overlap with the next temp entry |
| TEMP-0503222-4ACACF | XSS in book module in drupal |
| TEMP-0503222-760085 | local file inclusion in drupal |
| TEMP-0547140-24A459 | SA-CORE-2009-008 |