Drupal Drupal is an Open Source CMS written in PHP
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Drupal product.
RSS Feeds for Drupal security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Drupal products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Drupal Sorted by Most Security Vulnerabilities since 2018
Known Exploited Drupal Vulnerabilities
The following Drupal vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Drupal Core SQL Injection Vulnerability |
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. CVE-2026-9082 Exploit Probability: 33.7% |
May 22, 2026 |
| Drupal Core Remote Code Execution Vulnerability |
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CVE-2018-7602 Exploit Probability: 99.2% |
April 13, 2022 |
| Drupal Core Remote Code Execution Vulnerability |
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. CVE-2019-6340 Exploit Probability: 92.0% |
March 25, 2022 |
| Drupal core Un-restricted Upload of File |
Improper sanitization in the extension file names is present in Drupal core. CVE-2020-13671 Exploit Probability: 4.3% |
January 18, 2022 |
| Drupal module configuration vulnerability |
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. CVE-2018-7600 Exploit Probability: 100.0% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2026-9082: Drupal Core SQL Injection Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 106 vulnerabilities in Drupal with an average score of 5.9 out of ten. Last year, in 2025 Drupal had 43 security vulnerabilities published. That is, 63 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.02.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 106 | 5.86 |
| 2025 | 43 | 5.84 |
| 2024 | 12 | 6.30 |
| 2023 | 11 | 6.65 |
| 2022 | 20 | 7.11 |
| 2021 | 14 | 6.72 |
| 2020 | 9 | 8.00 |
| 2019 | 19 | 7.60 |
| 2018 | 5 | 8.30 |
It may take a day or so for new Drupal vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Drupal Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-11913 | Jul 10, 2026 |
CVE-2026-11913 Drupal Mother May I Unauth RCEvulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. |
|
| CVE-2026-11914 | Jul 10, 2026 |
Drupal Composer Vulnerability CVE-2026-11914: RCE via Composervulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. |
|
| CVE-2026-11915 | Jul 10, 2026 |
Drupal BruteForceProtection Vulnerability (CVE-2026-11915)vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. |
|
| CVE-2026-15087 | Jul 10, 2026 |
Drupal Clean RESTful: Remote Code Execution Vulnerabilityvulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. |
|
| CVE-2026-15086 | Jul 10, 2026 |
Drupal Raw Formatter (Meta Tag Formatter) XSS via Raw Inputvulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. |
|
| CVE-2026-15089 | Jul 10, 2026 |
Drupal Commerce Guest Reg RCE via Directory Traversalvulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. |
|
| CVE-2026-55808 | Jul 10, 2026 |
Drupal Core XSS Vulnerability Unpatched before 10.5.12,10.6.11,11.2.14,11.3.12Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. |
|
| CVE-2026-55807 | Jul 10, 2026 |
Drupal Core SSRF vulnerability (CVE-2026-55807) affecting 0.0.0-11.3.12Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. |
|
| CVE-2026-55806 | Jul 10, 2026 |
Drupal Core Open Redirect vulnerable 0.0.0-10.5.12/10.6.0-11.3.12URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. |
|
| CVE-2026-55804 | Jul 10, 2026 |
Drupal Core 0.0.011.3.12 OI: Improper DVA Object ModificationImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. |
|
| CVE-2026-55803 | Jul 10, 2026 |
Drupal core 11.3.12 Object Injection via Attribute ModificationImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. |
|
| CVE-2026-15085 | Jul 10, 2026 |
Stored XSS in Drupal AI SEO/GEO Analyzer 0.0.0-1.1.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3. |
|
| CVE-2026-15084 | Jul 10, 2026 |
Drupal UI Patterns 2.0.0-2.0.17 XSS (Stored)Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17. |
|
| CVE-2026-15083 | Jul 10, 2026 |
Drupal ECA Module Inject (0.0.02.1.20,3.0.03.0.12,3.1.03.1.4)Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4. |
|
| CVE-2026-15082 | Jul 10, 2026 |
Drupal Siteimprove Analytics XSS < 2.0.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1. |
|
| CVE-2026-15081 | Jul 10, 2026 |
Drupal Location Selector 1.3.0 SQLI via unescaped fieldImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0. |
|
| CVE-2026-15080 | Jul 10, 2026 |
Drupal Ray Enterprise Translate CSRF (0.0.0-4.0.4,4.1.0-4.1.4,11.0.0-11.0.4)Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4. |
|
| CVE-2026-58591 | Jul 10, 2026 |
Drupal Colorbox XSS (v 2.2.0) Improper Input NeutralizationImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0. |
|
| CVE-2026-15079 | Jul 10, 2026 |
Drupal Login Disable <=2.1.4 Brute Force via Improper Auth RestrictionImproper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4. |
|
| CVE-2026-58590 | Jul 10, 2026 |
Drupal FlowDrop <=1.6.0 Missing Auth: Forceful Browsing (CVE-2026-58590)Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. |
|
| CVE-2026-58589 | Jul 10, 2026 |
CVE-2026-58589: Drupal FlowDrop 0.0.0-1.6.0 Missing Auth: Forceful BrowsingMissing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. |
|
| CVE-2026-58588 | Jul 10, 2026 |
Drupal Canvas XSS before v1.7.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. |
|
| CVE-2026-58587 | Jul 10, 2026 |
Drupal Canvas XSS 0.0.01.4.2, 1.5.01.5.2, 1.6.01.6.1, 1.7.01.7.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. |
|
| CVE-2026-13244 | Jul 10, 2026 |
Drupal Tealium iQ TM Obj Inject (v<2.4.0)Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0. |
|
| CVE-2026-13243 | Jul 10, 2026 |
Drupal Salesforce Suite CSRF VULN (5.1.3)Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. |
|
| CVE-2026-13242 | Jul 10, 2026 |
Drupal Geolocation Field <=3.15.0 SQL Injection via unsanitized inputImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0. |
|
| CVE-2026-13241 | Jul 10, 2026 |
Drupal Paragraphs <=1.21.0: Missing Auth Forceful BrowsingMissing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. |
|
| CVE-2026-13240 | Jul 10, 2026 |
Drupal Paragraphs <=1.21.0 Missing Auth Enables Forceful BrowsingMissing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. |
|
| CVE-2026-13239 | Jul 10, 2026 |
Missing Auth: WissKI 0.0.0-4.2.0 Forceful BrowsingMissing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0. |
|
| CVE-2026-13238 | Jul 10, 2026 |
Drupal Commerce: Realex Incorrect Auth allows Forceful Browsing (<3.0.2)Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2. |
|
| CVE-2026-13237 | Jul 10, 2026 |
Drupal AI Agents <=1.3.1 Incorrect Auth: Forceful BrowsingIncorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. |
|
| CVE-2026-13236 | Jul 10, 2026 |
Missing Auth in Drupal AI Agents (v0.0.01.3.1) Allows Forceful BrowsingMissing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. |
|
| CVE-2026-13235 | Jul 10, 2026 |
Drupal AI Missing Auth v1.4.3 Forceful Browse (CVE-2026-13235)Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. |
|
| CVE-2026-13233 | Jul 10, 2026 |
Drupal OpenAI Provider SSRF v0.0.0-1.1.1 & 1.2.0-1.2.2Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. |
|
| CVE-2026-13234 | Jul 10, 2026 |
Drupal AI (0.0.01.4.3) XSS VulnerabilityImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. |
|
| CVE-2026-13232 | Jul 10, 2026 |
Drupal admin_feedback V02.8.0 Incorrect Auth Forceful BrowsingIncorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. |
|
| CVE-2026-13231 | Jul 10, 2026 |
Drupal Advanced Content Feedback Stored XSS pre-2.8.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. |
|
| CVE-2026-55810 | Jul 10, 2026 |
CVE-2026-55810: Object Injection in Drupal PlotlyJS Graphing <=3.0.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2. |
|
| CVE-2026-55809 | Jul 10, 2026 |
Drupal Flag Attendance Field <1.3: Improper Dynamic Obj Attr Mod (Obj Inj)Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. |
|
| CVE-2026-12535 | Jul 10, 2026 |
Drupal Formatter Field <=2.0.0 Object Injection via Dynamic AttributesImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. |
|
| CVE-2026-11909 | Jul 10, 2026 |
Drupal ExamplesTM for Developers <4.0.6: Missing Auth, Forceful BrowsingMissing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6. |
|
| CVE-2026-11908 | Jul 10, 2026 |
Drupal Tagify Stored XSS before 1.2.53Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Stored XSS. This issue affects Tagify versions: from 0.0.0 to 1.2.52. |
|
| CVE-2026-10770 | Jul 10, 2026 |
Drupal AntiSpam by CleanTalk Reflected XSS (pre9.7.2)Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1. |
|
| CVE-2026-10769 | Jul 10, 2026 |
Drupal Commerce 3.3.x Stored XSS VulnerabilityImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This issue affects Commerce Core versions: from 3.3.0 to 3.3.6. |
|
| CVE-2026-10768 | Jul 10, 2026 |
Drupal LocalGov Workflows 0.0.0-1.6.0 Missing Auth Forceful BrowsingMissing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. |
|
| CVE-2026-9726 | Jul 10, 2026 |
Drupal AlternativeCommerce OI IMCA Obj Injection 0.0.02.1.17Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17. |
|
| CVE-2026-6816 | May 28, 2026 |
Drupal TFA Basic Plugins < 1.2 Access Bypass via Admin UsersAn access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2. |
|
| CVE-2026-5343 | May 28, 2026 |
Drupal SAML SSO SP <3.1.4 Priv Esc via Condition CheckImproper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4. |
|
| CVE-2026-4093 | May 21, 2026 |
Drupal 7 Term Reference Tree module XSS; tokens unsanitized v7.x-1.11In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered. Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11. |
|
| CVE-2026-4929 | May 21, 2026 |
XSS in Drupal 7 SHS module (7.x-1.0 7.x-1.10) via term namesSimple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context. This affects versions from 7.x-1.0 through (and including) 7.x-1.10. |