Nathan Haug's vulnerability profile centers on a focused set of Drupal modules—Webform and FileField Sources—that extend core Drupal functionality for web forms and file handling. The recurring weaknesses reflect the input-processing role these modules play: cross-site scripting vulnerabilities from improper neutralization during page generation and information-disclosure flaws from unprotected sensitive data exposure. Defenders tracking Drupal installations should monitor this vendor's module updates as part of routine site hardening; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nathan Haug over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4533MEDIUM The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholders for a default value, which al | Dec 31, 2009 | 5.0 | 15 | NO | NO |
CVE-2009-4207MEDIUM Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web scrip | Dec 4, 2009 | 4.3 | 15 | NO | NO |
CVE-2013-4502MEDIUM The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read | May 13, 2014 | 4.0 | 14 | NO | NO |
CVE-2013-2129MEDIUM Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all | Jun 24, 2013 | 4.3 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" sourc | Dec 3, 2012 | 2.1 | 13 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select | Sep 18, 2012 | 2.1 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform creat | Dec 31, 2009 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nathan Haug.
Media articles that mention a CVE ID that affects a product developed by Nathan Haug — matched by CVE ID, not by vendor name.