NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25847 | CVE-2015-4389 | The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission. | 2 | 4 | Medium | 2017-01-19 | 2016-06-09 | View | |
| 25848 | CVE-2015-4390 | Multiple cross-site request forgery (CSRF) vulnerabilities in the User Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) continue or (2) delete an ongoing import via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-06-09 | View | |
| 25849 | CVE-2015-4391 | Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-06-09 | View | |
| 25850 | CVE-2015-4392 | Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-2.7 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to field display settings. | 2 | 3.5 | Low | 2017-01-19 | 2015-06-26 | View | |
| 25851 | CVE-2015-4393 | The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename. | 2 | 6 | Medium | 2017-01-19 | 2016-06-09 | View |
Page 14484 of 17672, showing 5 records out of 88360 total, starting on record 72416, ending on 72420