Drupal Drupal is an Open Source CMS written in PHP
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Drupal product.
RSS Feeds for Drupal security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Drupal products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Drupal Sorted by Most Security Vulnerabilities since 2018
Known Exploited Drupal Vulnerabilities
The following Drupal vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Drupal Core SQL Injection Vulnerability |
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. CVE-2026-9082 Exploit Probability: 33.7% |
May 22, 2026 |
| Drupal Core Remote Code Execution Vulnerability |
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. CVE-2018-7602 Exploit Probability: 99.2% |
April 13, 2022 |
| Drupal Core Remote Code Execution Vulnerability |
In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. CVE-2019-6340 Exploit Probability: 92.0% |
March 25, 2022 |
| Drupal core Un-restricted Upload of File |
Improper sanitization in the extension file names is present in Drupal core. CVE-2020-13671 Exploit Probability: 35.4% |
January 18, 2022 |
| Drupal module configuration vulnerability |
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. CVE-2018-7600 Exploit Probability: 100.0% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 2 known exploited Drupal vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 149 vulnerabilities in Drupal with an average score of 5.9 out of ten. Last year, in 2025 Drupal had 44 security vulnerabilities published. That is, 105 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.02
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 149 | 5.89 |
| 2025 | 44 | 5.91 |
| 2024 | 12 | 6.30 |
| 2023 | 11 | 6.65 |
| 2022 | 20 | 7.11 |
| 2021 | 14 | 6.72 |
| 2020 | 9 | 8.00 |
| 2019 | 19 | 7.60 |
| 2018 | 5 | 8.30 |
It may take a day or so for new Drupal vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Drupal Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-16647 | Sep 02, 2026 |
Drupal Disable Login Page Authentication Bypass (0.0.01.1.4) via Alternate PathAuthentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. |
|
| CVE-2026-18986 | Sep 02, 2026 |
Drupal Entity Browser XSS Stored <=2.16.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0. |
|
| CVE-2026-73475 | Sep 02, 2026 |
Drupal Commerce PayPal Incorrect Auth before 1.12.0 & 2.1.3Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. |
|
| CVE-2026-73478 | Sep 02, 2026 |
Drupal Diff <=2.1.1: Incorrect Auth Forceful BrowsingIncorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1. |
|
| CVE-2026-73474 | Sep 02, 2026 |
SSRF in Drupal EntityShareWebsub 0.0.0-1.1.2Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. |
|
| CVE-2026-73476 | Sep 02, 2026 |
Drupal External Auth: Improper Case Handling, v<2.0.13Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. |
|
| CVE-2026-73477 | Sep 02, 2026 |
Drupal Quick Tabs <=4.3.1 Incorrect Auth (Forceful Browsing)Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. |
|
| CVE-2026-76757 | Sep 02, 2026 |
Drupal Gammu SMS Daemon: RCE via Unvalidated SMS DataVulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. |
|
| CVE-2026-76756 | Sep 02, 2026 |
Drupal Gammu SMS Daemon: Potential RCE VulnerabilityVulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. |
|
| CVE-2026-76755 | Sep 02, 2026 |
php Drupal Gammu SMS Daemon Vulnerability (CVE-2026-76755)Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. |
|
| CVE-2026-76758 | Sep 02, 2026 |
Drupal Link Parser CVE-2026-76758 RCE via Malformed URLVulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. |
|
| CVE-2026-76782 | Sep 02, 2026 |
Drupal Screenshot: RCE VulnerabilityVulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. |
|
| CVE-2026-76759 | Sep 02, 2026 |
Drupal Screenshot RCE VulnerabilityVulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. |
|
| CVE-2026-81167 | Sep 02, 2026 |
Drupal Address Suggestion XSS (v0.0.0-1.0.25)Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25. |
|
| CVE-2026-81168 | Sep 02, 2026 |
Drupal CAPTCHA Protected Page Auth Bypass v0.0.01.0.2 (Alt Path)Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. |
|
| CVE-2026-81165 | Sep 02, 2026 |
Drupal Blazy 0.0.0-3.0.18 Incorrect Auth (Forceful Browsing)Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. |
|
| CVE-2026-81159 | Sep 02, 2026 |
CVE-2026-81159 Drupal Commerce CyberSource <=1.10 Brute ForceObservable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. |
|
| CVE-2026-81161 | Sep 02, 2026 |
Drupal CMN Privilege Escalation via Unsafe Actions (3.9.0)Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. |
|
| CVE-2026-81269 | Sep 02, 2026 |
Drupal Data Field 2.0.13 Missing Auth Enables Forceful BrowsingMissing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. |
|
| CVE-2026-81166 | Sep 02, 2026 |
Missing Auth in Drupal Digital Signage Framework (<=2.6.1) Allows Forceful BrowsingMissing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. |
|
| CVE-2026-81162 | Sep 02, 2026 |
Forceful Browsing via Sensitive Data Exposure in Drupal DXPR Builder <=2.8.1Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1. |
|
| CVE-2026-81158 | Sep 02, 2026 |
Drupal Entity API <=1.8.0 Auth Bypass Forceful BrowsingIncorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. |
|
| CVE-2026-81164 | Sep 02, 2026 |
Missing Auth in Drupal Entity PDF 0.0.0-2.1.5 Forceful BrowsingMissing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. |
|
| CVE-2026-81205 | Sep 02, 2026 |
Drupal LDAP Integration LDAP Injection before 2.2.1Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. |
|
| CVE-2026-81201 | Sep 02, 2026 |
Drupal Monster Menus Stored XSS v0.0.09.5.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3. |
|
| CVE-2026-81160 | Sep 02, 2026 |
Drupal Slick Carousel <2.1.0 Stored XSS VulnerabilityImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. |
|
| CVE-2026-15916 | Aug 25, 2026 |
Drupal Core Missing Auth (Forceful Browsing) Fixed 10.6.14, 11.3.15, 11.4.5Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. |
|
| CVE-2026-15917 | Aug 25, 2026 |
Drupal XSS in Core 0.0.011.4.4, fixed in 11.4.5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*. |
|
| CVE-2026-55805 | Aug 25, 2026 |
Drupal core Stored XSS before 10.6.13, 11.3.14, 11.4.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. |
|
| CVE-2026-16638 | Aug 25, 2026 |
Drupal Media Folders 0.0.01.0.8 Stored XSSImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. |
|
| CVE-2026-16639 | Aug 25, 2026 |
Drupal i18n SSO Authentication Bypass v<1.8.0 via Alternate PathAuthentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. |
|
| CVE-2026-16640 | Aug 25, 2026 |
Drupal Search API Autocomplete <=1.12.0 Reflected XSSImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0. |
|
| CVE-2026-16646 | Aug 25, 2026 |
Drupal PanKM RCE via Unrestricted File Upload CVE-2026-16646Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*. |
|
| CVE-2026-16641 | Aug 25, 2026 |
Drupal Commerce Elavon: Payment Module Vulnerability (CVE-2026-16641)Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. |
|
| CVE-2026-16642 | Aug 25, 2026 |
Drupal Email Login OTP: RCE via Unvalidated InputVulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. |
|
| CVE-2026-16643 | Aug 25, 2026 |
Drupal Lunr Exposed Filters VulnerabilityVulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. |
|
| CVE-2026-16644 | Aug 25, 2026 |
Unauthorized Access in Drupal Webform REST <=4.1.0 Allows Forceful BrowsingIncorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. |
|
| CVE-2026-16645 | Aug 25, 2026 |
Drupal PhotoSwipe Missing Auth (0.0.0-3.2.0) Forceful BrowsingMissing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. |
|
| CVE-2026-15088 | Aug 25, 2026 |
Drupal Devel Env RCE in Dev EnvironmentVulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. |
|
| CVE-2026-18259 | Aug 25, 2026 |
Drupal Token Content Access Timing Brute Force (3.1.2)Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. |
|
| CVE-2026-18260 | Aug 25, 2026 |
Drupal Disable Login Page RCE via Improper Input ValidationImproper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. |
|
| CVE-2026-18261 | Aug 25, 2026 |
CVE-2026-18261: Drupal Powerful Surveys VulnerabilityVulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. |
|
| CVE-2026-18985 | Aug 25, 2026 |
Drupal Edit_in-place Field <=2.1.1 Incorrect Authorization Forceful BrowsingIncorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. |
|
| CVE-2026-11913 | Jul 10, 2026 |
CVE-2026-11913 Drupal Mother May I Unauth RCEvulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. |
|
| CVE-2026-11914 | Jul 10, 2026 |
Drupal Composer Vulnerability CVE-2026-11914: RCE via Composervulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. |
|
| CVE-2026-11915 | Jul 10, 2026 |
Drupal BruteForceProtection Vulnerability (CVE-2026-11915)vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. |
|
| CVE-2026-15087 | Jul 10, 2026 |
Drupal Clean RESTful: Remote Code Execution Vulnerabilityvulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. |
|
| CVE-2026-15086 | Jul 10, 2026 |
Drupal Raw Formatter (Meta Tag Formatter) XSS via Raw Inputvulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. |
|
| CVE-2026-15089 | Jul 10, 2026 |
Drupal Commerce Guest Reg RCE via Directory TraversalVulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*. |
|
| CVE-2026-55808 | Jul 10, 2026 |
Drupal Core XSS Vulnerability Unpatched before 10.5.12,10.6.11,11.2.14,11.3.12Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. |
|