Steven Jones maintains a narrowly scoped vulnerability footprint concentrated in the Context product, with the durable signal centered on application-layer code-handling issues such as code injection and cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Steven Jones over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4446MEDIUM The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that | Dec 7, 2013 | 6.8 | 18 | NO | NO |
CVE-2012-5655MEDIUM The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain se | Jan 3, 2013 | 5.0 | 17 | NO | NO |
CVE-2013-4445MEDIUM The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which m | Dec 7, 2013 | 4.9 | 15 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitra | May 19, 2010 | 2.1 | 12 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Steven Jones.
Media articles that mention a CVE ID that affects a product developed by Steven Jones — matched by CVE ID, not by vendor name.