Drupal records
863 published records for vendor drupal.
Researcher profile
- Entered KEV
- 8 · 0.9%
- Weaponized
- 13 · 1.5%
- Pre-auth RCE
- 60
- With a fix record
- 24.6%
- Median publish → KEV
- 886 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')360
- CWE-264 Permissions, Privileges, and Access Controls130
- CWE-352 Cross-Site Request Forgery (CSRF)67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')33
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor30
- CWE-20 Improper Input Validation29
The weakness classes this vendor ships most often: where to look.
CWEAll records
863 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2018-7600Weaponized | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because odrupal · drupal · CWE-20 | Critical9.8 | KEV | 100.0% | Mar 29, 2018 |
99Now | CVE-2018-7602Weaponized | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Critical9.8 | KEV | 99.2% | Jul 19, 2018 |
90Now | CVE-2019-6340Weaponized | Drupal core - Highly critical - Remote Code Executiondrupal · drupal · CWE-502 | High8.1 | KEV | 92.0% | Feb 21, 2019 |
86Now | CVE-2020-28949Weaponized | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | High7.8 | KEV | 84.6% | Nov 19, 2020 |
81Now | CVE-2020-36193Weaponized | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relatphp · archive tar · CWE-22 | High7.5 | KEV | 70.6% | Jan 18, 2021 |
79This week | CVE-2020-11023Weaponized | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Medium6.1 | KEV | 84.9% | Apr 29, 2020 |
76This week | CVE-2020-13671Weaponized | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extendrupal · drupal · CWE-434 | High8.8 | KEV | 35.4% | Nov 20, 2020 |
74This week | CVE-2026-9082Weaponized | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004drupal · drupal · CWE-89 | Critical9.8 | KEV | 15.7% | May 20, 2026 |
60This week | CVE-2014-3704Weaponized | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,drupal · drupal · CWE-89 | High7.5 | — | 100.0% | Oct 15, 2014 |
54Plan | CVE-2020-11022Proof of concept | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Medium6.1 | — | 99.2% | Apr 29, 2020 |
54Plan | CVE-2005-1921Weaponized | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1php · xml rpc · CWE-94 | High7.5 | — | 79.1% | Jul 5, 2005 |
50Plan | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Medium6.1 | — | 87.2% | Apr 19, 2019 |
50Plan | CVE-2019-6339Proof of concept | PHAR stream wrapper Arbitrary PHP code executiondrupal · drupal · CWE-20 | Critical9.8 | — | 35.6% | Jan 22, 2019 |
47Plan | CVE-2018-9205Proof of concept | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.drupal · avatar uploader · CWE-22 | High7.5 | — | 55.1% | Apr 4, 2018 |
47Plan | CVE-2016-5385No exploit | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | High8.1 | — | 50.4% | Jul 18, 2016 |
45Plan | CVE-2014-9016Weaponized | The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allodrupal · drupal | Medium5.0 | — | 82.2% | Nov 24, 2014 |
45Plan | CVE-2020-28948Proof of concept | Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.php · archive tar · CWE-502 | High7.8 | — | 47.5% | Nov 19, 2020 |
45Plan | CVE-2017-6920No exploit | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects sdrupal · drupal · CWE-19 | Critical9.8 | — | 20.5% | Aug 6, 2018 |
43Plan | CVE-2018-14773No exploit | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13sensiolabs · symfony | Medium6.5 | — | 58.1% | Aug 3, 2018 |
41Plan | CVE-2019-10910No exploit | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inpsensiolabs · symfony · CWE-89 | Critical9.8 | — | 6.0% | May 16, 2019 |
41Plan | CVE-2019-11831No exploit | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversaltypo3 · pharstreamwrapper · CWE-22 | Critical9.8 | — | 5.4% | May 9, 2019 |
41Plan | CVE-2008-0568No exploit | Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackerdrupal · secure site module | Critical10.0 | — | 2.4% | Feb 4, 2008 |
41Plan | CVE-2008-0823No exploit | Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vidrupal · header image · CWE-287 | Critical10.0 | — | 2.2% | Feb 19, 2008 |
41Plan | CVE-2013-0318No exploit | The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended resdrupal · drupal · CWE-264 | Critical10.0 | — | 2.0% | Mar 27, 2013 |
41Plan | CVE-2009-3352No exploit | Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.drupal · drupal | Critical10.0 | — | 2.0% | Sep 24, 2009 |
- CVE-2018-760099Now
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because o
CriticalCVSS 9.8KEVWeaponizedEPSS 100%drupal · drupalMar 29, 2018
- CVE-2018-760299Now
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
CriticalCVSS 9.8KEVWeaponizedEPSS 99%drupal · drupalJul 19, 2018
- CVE-2019-634090Now
Drupal core - Highly critical - Remote Code Execution
HighCVSS 8.1KEVWeaponizedEPSS 92%drupal · drupalFeb 21, 2019
- CVE-2020-2894986Now
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
HighCVSS 7.8KEVWeaponizedEPSS 85%php · archive tarNov 19, 2020
- CVE-2020-3619381Now
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat
HighCVSS 7.5KEVWeaponizedEPSS 71%php · archive tarJan 18, 2021
- CVE-2020-1102379This week
Potential XSS vulnerability in jQuery
MediumCVSS 6.1KEVWeaponizedEPSS 85%jquery · jqueryApr 29, 2020
- CVE-2020-1367176This week
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten
HighCVSS 8.8KEVWeaponizedEPSS 35%drupal · drupalNov 20, 2020
- CVE-2026-908274This week
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
CriticalCVSS 9.8KEVWeaponizedEPSS 16%drupal · drupalMay 20, 2026
- CVE-2014-370460This week
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements,
HighCVSS 7.5WeaponizedEPSS 100%drupal · drupalOct 15, 2014
- CVE-2020-1102254Plan
jQuery has a potential XSS vulnerability
MediumCVSS 6.1Proof of conceptEPSS 99%jquery · jqueryApr 29, 2020
- CVE-2005-192154Plan
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1
HighCVSS 7.5WeaponizedEPSS 79%php · xml rpcJul 5, 2005
- CVE-2019-1135850Plan
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
MediumCVSS 6.1Proof of conceptEPSS 87%jquery · jqueryApr 19, 2019
- CVE-2019-633950Plan
PHAR stream wrapper Arbitrary PHP code execution
CriticalCVSS 9.8Proof of conceptEPSS 36%drupal · drupalJan 22, 2019
- CVE-2018-920547Plan
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
HighCVSS 7.5Proof of conceptEPSS 55%drupal · avatar uploaderApr 4, 2018
- CVE-2016-538547Plan
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
HighCVSS 8.1No exploitEPSS 50%hp · storeever msl6480 tape library firmwareJul 18, 2016
- CVE-2014-901645Plan
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allo
MediumCVSS 5.0WeaponizedEPSS 82%drupal · drupalNov 24, 2014
- CVE-2020-2894845Plan
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
HighCVSS 7.8Proof of conceptEPSS 47%php · archive tarNov 19, 2020
- CVE-2017-692045Plan
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s
CriticalCVSS 9.8No exploitEPSS 20%drupal · drupalAug 6, 2018
- CVE-2018-1477343Plan
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13
MediumCVSS 6.5No exploitEPSS 58%sensiolabs · symfonyAug 3, 2018
- CVE-2019-1091041Plan
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user inp
CriticalCVSS 9.8No exploitEPSS 6%sensiolabs · symfonyMay 16, 2019
- CVE-2019-1183141Plan
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal
CriticalCVSS 9.8No exploitEPSS 5%typo3 · pharstreamwrapperMay 9, 2019
- CVE-2008-056841Plan
Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attacker
CriticalCVSS 10.0No exploitEPSS 2%drupal · secure site moduleFeb 4, 2008
- CVE-2008-082341Plan
Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages vi
CriticalCVSS 10.0No exploitEPSS 2%drupal · header imageFeb 19, 2008
- CVE-2013-031841Plan
The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended res
CriticalCVSS 10.0No exploitEPSS 2%drupal · drupalMar 27, 2013
- CVE-2009-335241Plan
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%drupal · drupalSep 24, 2009