The Restful Web Services Project maintains a narrowly scoped product focused on web service development and integration, where vulnerabilities cluster around application-layer security boundaries. The recurring weakness classes—including cross-site request forgery, code injection, input validation failures, and exposure of sensitive data through queries—reflect the inherent risks of handling untrusted web requests and managing access to backend resources. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Restful Web Services Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4225HIGH The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it e | Feb 11, 2020 | 8.8 | 22 | NO | NO |
CVE-2013-0205MEDIUM Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attack | Mar 19, 2013 | 6.8 | 21 | NO | NO |
CVE-2012-5556MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow rem | Dec 3, 2012 | 6.8 | 21 | NO | NO |
CVE-2024-13255HIGH Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 b | Jan 9, 2025 | 7.5 | 19 | NO | NO |
CVE-2015-4345MEDIUM The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allow | Jun 15, 2015 | 5.0 | 15 | NO | NO |
CVE-2013-1946MEDIUM The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS p | Apr 6, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Restful Web Services Project.
Media articles that mention a CVE ID that affects a product developed by Restful Web Services Project — matched by CVE ID, not by vendor name.