Moshe Weitzman contributes to a narrow set of Drupal-ecosystem modules focused on organic group management and development utilities, with a modest but durable vulnerability footprint centered on web-application input handling. The recurring weakness class observed across disclosures is cross-site scripting, a characteristic finding in web modules where user input and content rendering intersect. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moshe Weitzman over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2721MEDIUM The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, | Jun 27, 2012 | 6.8 | 21 | NO | NO |
CVE-2009-4528MEDIUM The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restrictions, and create, modify, or rea | Dec 31, 2009 | 6.5 | 19 | NO | NO |
CVE-2012-2081MEDIUM The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private gr | Aug 14, 2012 | 5.0 | 17 | NO | NO |
CVE-2009-3786MEDIUM Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitra | Oct 26, 2009 | 4.3 | 15 | NO | NO |
CVE-2009-3435MEDIUM Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inje | Sep 28, 2009 | 4.3 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authen | Jun 27, 2012 | 2.1 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authe | Oct 9, 2009 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moshe Weitzman.
Media articles that mention a CVE ID that affects a product developed by Moshe Weitzman — matched by CVE ID, not by vendor name.