nancy_wichmann CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

nancy_wichmann vulnerability overview

Aggregates CVE and security vulnerability intelligence across all nancy_wichmann-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2012-4500 The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possibly have other unspecified impact. [email protected] 3.5 0.26% 2012-10-31 2026-04-29
CVE-2012-2298 Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks." [email protected] 4.3 0.67% 2012-08-14 2026-04-29
CVE-2012-2302 Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive information via unspecified vectors. [email protected] 5.0 0.52% 2012-07-25 2026-04-29
CVE-2012-2711 Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy List module 6.x-1.x before 6.x-1.4 for Drupal allow remote authenticated users with create or edit taxonomy terms permissions to inject arbitrary web script or HTML via vectors related to taxonomy information. [email protected] 2.1 0.28% 2012-06-27 2026-04-29
CVE-2012-2339 Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "taxonomy information." [email protected] 4.3 0.92% 2012-05-21 2026-04-29
CVE-2009-4524 Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (aka real name) element. [email protected] 4.3 0.40% 2009-12-31 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence