Karen Stevenson's vulnerability footprint centers on a small set of web-based applications and tools including CCK, Date, and Calendar, with the recurring signal anchored in application-layer input-handling issues such as cross-site scripting, SQL injection, and improper input validation. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Karen Stevenson over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1626MEDIUM SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools | Sep 20, 2012 | 6.0 | 20 | NO | NO |
CVE-2010-2352MEDIUM The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced | Jun 21, 2010 | 5.0 | 17 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inje | Sep 10, 2009 | 3.5 | 13 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissi | Aug 13, 2009 | 3.5 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or " | Sep 10, 2009 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Karen Stevenson.
Media articles that mention a CVE ID that affects a product developed by Karen Stevenson — matched by CVE ID, not by vendor name.