Drupal Core-Recommended vulnerabilities

6 known vulnerabilities affecting drupal/core-recommended.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2024-55638HIGH≥ 8.8.0, < 10.2.11≥ 10.3.0, < 10.3.9+1 more2024-12-10
CVE-2024-55638 [HIGH] CWE-502 Drupal core contains a potential PHP Object Injection vulnerability Drupal core contains a potential PHP Object Injection vulnerability Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Remote Code Execution. It is not directly exploitable. This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe in
ghsaosv
CVE-2024-55637HIGH≥ 8.8.0, < 10.2.11≥ 10.3.0, < 10.3.9+1 more2024-12-10
CVE-2024-55637 [HIGH] CWE-502 Drupal core contains a potential PHP Object Injection vulnerability Drupal core contains a potential PHP Object Injection vulnerability Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Remote Code Execution. It is not directly exploitable. This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe in
ghsaosv
CVE-2024-55634MEDIUM≥ 8.0.0, < 10.2.11≥ 10.3.0, < 10.3.9+1 more2024-12-10
CVE-2024-55634 [MEDIUM] CWE-178 Drupal core Access bypass Drupal core Access bypass Drupal's uniqueness checking for certain user fields is inconsistent depending on the database engine and its collation. As a result, a user may be able to register with the same email address as another user. This may lead to data integrity issues. This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
ghsaosv
CVE-2024-12393MEDIUM≥ 8.8.0, < 10.2.11≥ 10.3.0, < 10.3.9+1 more2024-12-10
CVE-2024-12393 [MEDIUM] CWE-79 Drupal Core Cross-Site Scripting (XSS) Drupal Core Cross-Site Scripting (XSS) Drupal uses JavaScript to render status messages in some cases and configurations. In certain situations, the status messages are not adequately sanitized. This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
ghsaosv
CVE-2024-55636LOW≥ 8.8.0, < 10.2.11≥ 10.3.0, < 10.3.9+1 more2024-12-10
CVE-2024-55636 [LOW] CWE-502 Drupal core contains a potential PHP Object Injection vulnerability Drupal core contains a potential PHP Object Injection vulnerability Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Artbitrary File Deletion. It is not directly exploitable. This issue is mitigated by the fact that in order to be exploitable, a separate vulnerability must be present that allows an attacker to pass unsafe inpu
ghsaosv
CVE-2024-45440MEDIUMPoC≥ 10.3.0, < 10.3.6≥ 11.0.0, < 11.0.5+1 more2024-08-29
CVE-2024-45440 [MEDIUM] CWE-209 Drupal Full Path Disclosure Drupal Full Path Disclosure `core/authorize.php` in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of `hash_salt` is `file_get_contents` of a file that does not exist.
ghsaosv