Views Project maintains a focused Drupal module for content organization and display, with observed vulnerabilities centered on web application security issues including sensitive-information exposure and cross-site scripting in user-facing components. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Views Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5490MEDIUM The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which a | Aug 18, 2015 | 5.0 | 17 | NO | NO |
CVE-2015-3378MEDIUM Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remo | Apr 21, 2015 | 4.9 | 15 | NO | NO |
CVE-2015-3379MEDIUM The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows | Apr 21, 2015 | 4.0 | 14 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitr | Mar 27, 2013 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Views Project.
Media articles that mention a CVE ID that affects a product developed by Views Project — matched by CVE ID, not by vendor name.