Drupal Drupal Drupal is an Open Source CMS written in PHP

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Drupal product.

RSS Feeds for Drupal security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Drupal products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Drupal Sorted by Most Security Vulnerabilities since 2018

Drupal144 vulnerabilities
CMS

Drupal Wiki1 vulnerability

Drupal Web T1 vulnerability

Drupal Svg Sanitizer1 vulnerability

Drupal Responsive Menus1 vulnerability

Drupal Panels1 vulnerability

Drupal Obfuscate1 vulnerability

Drupal Entity Embed1 vulnerability

Drupal Eca1 vulnerability

Drupal Docker Images1 vulnerability

Drupal Avatar Uploader1 vulnerability

Known Exploited Drupal Vulnerabilities

The following Drupal vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Drupal Core SQL Injection Vulnerability Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-9082 Exploit Probability: 33.7%
May 22, 2026
Drupal Core Remote Code Execution Vulnerability A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7602 Exploit Probability: 99.2%
April 13, 2022
Drupal Core Remote Code Execution Vulnerability In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2019-6340 Exploit Probability: 92.0%
March 25, 2022
Drupal core Un-restricted Upload of File Improper sanitization in the extension file names is present in Drupal core.
CVE-2020-13671 Exploit Probability: 35.4%
January 18, 2022
Drupal module configuration vulnerability Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVE-2018-7600 Exploit Probability: 100.0%
November 3, 2021

Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 2 known exploited Drupal vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 149 vulnerabilities in Drupal with an average score of 5.9 out of ten. Last year, in 2025 Drupal had 44 security vulnerabilities published. That is, 105 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.02




Year Vulnerabilities Average Score
2026 149 5.89
2025 44 5.91
2024 12 6.30
2023 11 6.65
2022 20 7.11
2021 14 6.72
2020 9 8.00
2019 19 7.60
2018 5 8.30

It may take a day or so for new Drupal vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Drupal Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-16647 Sep 02, 2026
Drupal Disable Login Page Authentication Bypass (0.0.01.1.4) via Alternate Path Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
CVE-2026-18986 Sep 02, 2026
Drupal Entity Browser XSS Stored <=2.16.0 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.
CVE-2026-73475 Sep 02, 2026
Drupal Commerce PayPal Incorrect Auth before 1.12.0 & 2.1.3 Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
CVE-2026-73478 Sep 02, 2026
Drupal Diff <=2.1.1: Incorrect Auth Forceful Browsing Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
CVE-2026-73474 Sep 02, 2026
SSRF in Drupal EntityShareWebsub 0.0.0-1.1.2 Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.
CVE-2026-73476 Sep 02, 2026
Drupal External Auth: Improper Case Handling, v<2.0.13 Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
CVE-2026-73477 Sep 02, 2026
Drupal Quick Tabs <=4.3.1 Incorrect Auth (Forceful Browsing) Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
CVE-2026-76757 Sep 02, 2026
Drupal Gammu SMS Daemon: RCE via Unvalidated SMS Data Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76756 Sep 02, 2026
Drupal Gammu SMS Daemon: Potential RCE Vulnerability Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76755 Sep 02, 2026
php Drupal Gammu SMS Daemon Vulnerability (CVE-2026-76755) Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76758 Sep 02, 2026
Drupal Link Parser CVE-2026-76758 RCE via Malformed URL Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.
CVE-2026-76782 Sep 02, 2026
Drupal Screenshot: RCE Vulnerability Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
CVE-2026-76759 Sep 02, 2026
Drupal Screenshot RCE Vulnerability Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
CVE-2026-81167 Sep 02, 2026
Drupal Address Suggestion XSS (v0.0.0-1.0.25) Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
CVE-2026-81168 Sep 02, 2026
Drupal CAPTCHA Protected Page Auth Bypass v0.0.01.0.2 (Alt Path) Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
CVE-2026-81165 Sep 02, 2026
Drupal Blazy 0.0.0-3.0.18 Incorrect Auth (Forceful Browsing) Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
CVE-2026-81159 Sep 02, 2026
CVE-2026-81159 Drupal Commerce CyberSource <=1.10 Brute Force Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
CVE-2026-81161 Sep 02, 2026
Drupal CMN Privilege Escalation via Unsafe Actions (3.9.0) Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
CVE-2026-81269 Sep 02, 2026
Drupal Data Field 2.0.13 Missing Auth Enables Forceful Browsing Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
CVE-2026-81166 Sep 02, 2026
Missing Auth in Drupal Digital Signage Framework (<=2.6.1) Allows Forceful Browsing Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
CVE-2026-81162 Sep 02, 2026
Forceful Browsing via Sensitive Data Exposure in Drupal DXPR Builder <=2.8.1 Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
Drupal
CVE-2026-81158 Sep 02, 2026
Drupal Entity API <=1.8.0 Auth Bypass Forceful Browsing Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
CVE-2026-81164 Sep 02, 2026
Missing Auth in Drupal Entity PDF 0.0.0-2.1.5 Forceful Browsing Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.
CVE-2026-81205 Sep 02, 2026
Drupal LDAP Integration LDAP Injection before 2.2.1 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
CVE-2026-81201 Sep 02, 2026
Drupal Monster Menus Stored XSS v0.0.09.5.3 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.
CVE-2026-81160 Sep 02, 2026
Drupal Slick Carousel <2.1.0 Stored XSS Vulnerability Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.
CVE-2026-15916 Aug 25, 2026
Drupal Core Missing Auth (Forceful Browsing) Fixed 10.6.14, 11.3.15, 11.4.5 Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Drupal
CVE-2026-15917 Aug 25, 2026
Drupal XSS in Core 0.0.011.4.4, fixed in 11.4.5 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
Drupal
CVE-2026-55805 Aug 25, 2026
Drupal core Stored XSS before 10.6.13, 11.3.14, 11.4.4 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Drupal
CVE-2026-16638 Aug 25, 2026
Drupal Media Folders 0.0.01.0.8 Stored XSS Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.
CVE-2026-16639 Aug 25, 2026
Drupal i18n SSO Authentication Bypass v<1.8.0 via Alternate Path Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
CVE-2026-16640 Aug 25, 2026
Drupal Search API Autocomplete <=1.12.0 Reflected XSS Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.
CVE-2026-16646 Aug 25, 2026
Drupal PanKM RCE via Unrestricted File Upload CVE-2026-16646 Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
CVE-2026-16641 Aug 25, 2026
Drupal Commerce Elavon: Payment Module Vulnerability (CVE-2026-16641) Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
CVE-2026-16642 Aug 25, 2026
Drupal Email Login OTP: RCE via Unvalidated Input Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
CVE-2026-16643 Aug 25, 2026
Drupal Lunr Exposed Filters Vulnerability Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
CVE-2026-16644 Aug 25, 2026
Unauthorized Access in Drupal Webform REST <=4.1.0 Allows Forceful Browsing Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
CVE-2026-16645 Aug 25, 2026
Drupal PhotoSwipe Missing Auth (0.0.0-3.2.0) Forceful Browsing Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
CVE-2026-15088 Aug 25, 2026
Drupal Devel Env RCE in Dev Environment Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
CVE-2026-18259 Aug 25, 2026
Drupal Token Content Access Timing Brute Force (3.1.2) Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.
CVE-2026-18260 Aug 25, 2026
Drupal Disable Login Page RCE via Improper Input Validation Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
CVE-2026-18261 Aug 25, 2026
CVE-2026-18261: Drupal Powerful Surveys Vulnerability Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
CVE-2026-18985 Aug 25, 2026
Drupal Edit_in-place Field <=2.1.1 Incorrect Authorization Forceful Browsing Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.
CVE-2026-11913 Jul 10, 2026
CVE-2026-11913 Drupal Mother May I Unauth RCE vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
CVE-2026-11914 Jul 10, 2026
Drupal Composer Vulnerability CVE-2026-11914: RCE via Composer vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
CVE-2026-11915 Jul 10, 2026
Drupal BruteForceProtection Vulnerability (CVE-2026-11915) vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
CVE-2026-15087 Jul 10, 2026
Drupal Clean RESTful: Remote Code Execution Vulnerability vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
CVE-2026-15086 Jul 10, 2026
Drupal Raw Formatter (Meta Tag Formatter) XSS via Raw Input vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
CVE-2026-15089 Jul 10, 2026
Drupal Commerce Guest Reg RCE via Directory Traversal Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
CVE-2026-55808 Jul 10, 2026
Drupal Core XSS Vulnerability Unpatched before 10.5.12,10.6.11,11.2.14,11.3.12 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Drupal
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.