Organic Groups Project develops a community-engagement and group-management plugin whose vulnerability surface centers on authorization and information-exposure weaknesses. These recurring classes reflect the sensitivity of membership data and access controls in collaborative platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Organic Groups Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7065MEDIUM The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups via a group audience field, as d | Apr 29, 2014 | 5.8 | 20 | NO | NO |
CVE-2013-7068MEDIUM The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via a | Apr 29, 2014 | 4.9 | 18 | NO | NO |
The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary | Dec 3, 2012 | 3.5 | 16 | NO | NO |
CVE-2013-4228MEDIUM The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which a | Feb 18, 2020 | 4.3 | 14 | NO | NO |
CVE-2008-3094MEDIUM The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via | Jul 9, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Organic Groups Project.
Media articles that mention a CVE ID that affects a product developed by Organic Groups Project — matched by CVE ID, not by vendor name.