Navigate Project maintains a focused web application product centered on navigation and related functionality, with its vulnerability profile concentrated around input-handling issues in web contexts, particularly cross-site scripting weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Navigate Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via uns | Aug 18, 2015 | 3.5 | 13 | NO | NO |
CVE-2015-5499MEDIUM The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveragin | Aug 18, 2015 | 4.0 | 13 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Navigate Project.
Media articles that mention a CVE ID that affects a product developed by Navigate Project — matched by CVE ID, not by vendor name.