Earl Miles develops the Views and Panels modules, widely used components of the Drupal content management system that extend data display and page layout capabilities. The vulnerability profile concentrates on web-application input-handling issues, including cross-site scripting, cross-site request forgery, and SQL injection, reflecting the challenges of safely processing and rendering user-supplied content within a shared CMS framework. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Earl Miles over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4113HIGH SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on ce | Feb 17, 2012 | 7.5 | 23 | NO | NO |
CVE-2012-0914MEDIUM Cross-site scripting (XSS) vulnerability in display_renderers/panels_renderer_editor.class.php in the admin view in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before 7.x | Jan 24, 2012 | 4.3 | 18 | NO | NO |
CVE-2010-4519MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote att | Dec 23, 2010 | 6.8 | 18 | NO | NO |
CVE-2010-4521MEDIUM Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path. | Dec 23, 2010 | 4.3 | 17 | NO | NO |
CVE-2010-4520MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL o | Dec 23, 2010 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Earl Miles.
Media articles that mention a CVE ID that affects a product developed by Earl Miles — matched by CVE ID, not by vendor name.