AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-0507

MEDIUM · CVSS 6 EPSS 1.00%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-01-26 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-0507
Severity
MEDIUM
CVSS
6
EPSS
1.00%

Original Filing — NVD Description

SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.