CVE-2015-5502: Storage API Project Storage API

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors.

Affected products

  • Storage API Project Storage API: version 7.x-1.0 only; version 7.x-1.1 only; version 7.x-1.2 only; version 7.x-1.3 only; version 7.x-1.4 only; version 7.x-1.5 only; …

Published 2015-08-18. Last modified 2026-06-17.