VendorsNavigate Projectnavigateall versions
Vulnerabilities

Navigate Project Navigate

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-5499
The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveraging the "navigate view" permission.
Published 2015-08-18 · Modified
4.0EPSS 0.009
CVE-2015-5500
Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-08-18 · Modified
3.5EPSS 0.008