services_project CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

services_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all services_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting, vendor risk csrf, and vendor risk input validation, with potential vendor impact unexpected behavior across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2015-4394 The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified vectors. [email protected] 5.0 1.42% 2015-06-15 2026-05-06
CVE-2015-4393 The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename. [email protected] 6.0 1.71% 2015-06-15 2026-05-06
CVE-2014-9153 Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response. [email protected] 4.3 0.93% 2014-12-01 2026-05-06
CVE-2014-9152 The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack. [email protected] 7.5 2.33% 2014-12-01 2026-05-06
CVE-2014-9151 The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password. [email protected] 7.5 1.40% 2014-12-01 2026-05-06
CVE-2013-2158 Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. [email protected] 6.8 0.73% 2013-07-01 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence