Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Entity Api Project Subscribe
Filtered by product Entity Api
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-1398 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2018-05-18 4.0 MEDIUM 6.5 MEDIUM
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
CVE-2014-1400 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2018-05-18 4.0 MEDIUM 6.5 MEDIUM
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
CVE-2014-1399 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2018-05-18 4.0 MEDIUM 6.5 MEDIUM
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
CVE-2015-2197 1 Entity Api Project 1 Entity Api 2015-03-04 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.
CVE-2013-4273 1 Entity Api Project 1 Entity Api 2015-02-27 4.0 MEDIUM N/A
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows remote authenticated users to read the comments via unspecified vectors. NOTE: this identifier was SPLIT per ADT5 due to different researcher organizations. CVE-2013-7391 was assigned for the View vector.
CVE-2013-7391 1 Entity Api Project 1 Entity Api 2015-02-27 5.0 MEDIUM N/A
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) footer of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5 due to different researcher organizations.