Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Password Policy Project Subscribe
Filtered by product Password Policy
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4387 1 Password Policy Project 1 Password Policy 2015-06-26 2.6 LOW N/A
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.