Drupal Drupal Drupal is an Open Source CMS written in PHP

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Drupal product.

RSS Feeds for Drupal security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Drupal products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Drupal Sorted by Most Security Vulnerabilities since 2018

Drupal140 vulnerabilities
CMS

Drupal Wiki1 vulnerability

Drupal Web T1 vulnerability

Drupal Svg Sanitizer1 vulnerability

Drupal Responsive Menus1 vulnerability

Drupal Panels1 vulnerability

Drupal Obfuscate1 vulnerability

Drupal Entity Embed1 vulnerability

Drupal Eca1 vulnerability

Drupal Docker Images1 vulnerability

Drupal Avatar Uploader1 vulnerability

Known Exploited Drupal Vulnerabilities

The following Drupal vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Drupal Core SQL Injection Vulnerability Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-9082 Exploit Probability: 33.7%
May 22, 2026
Drupal Core Remote Code Execution Vulnerability A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7602 Exploit Probability: 99.2%
April 13, 2022
Drupal Core Remote Code Execution Vulnerability In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CVE-2019-6340 Exploit Probability: 92.0%
March 25, 2022
Drupal core Un-restricted Upload of File Improper sanitization in the extension file names is present in Drupal core.
CVE-2020-13671 Exploit Probability: 4.3%
January 18, 2022
Drupal module configuration vulnerability Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
CVE-2018-7600 Exploit Probability: 100.0%
November 3, 2021

Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2026-9082: Drupal Core SQL Injection Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

By the Year

In 2026 there have been 106 vulnerabilities in Drupal with an average score of 5.9 out of ten. Last year, in 2025 Drupal had 43 security vulnerabilities published. That is, 63 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.02.




Year Vulnerabilities Average Score
2026 106 5.86
2025 43 5.84
2024 12 6.30
2023 11 6.65
2022 20 7.11
2021 14 6.72
2020 9 8.00
2019 19 7.60
2018 5 8.30

It may take a day or so for new Drupal vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Drupal Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-11913 Jul 10, 2026
CVE-2026-11913 Drupal Mother May I Unauth RCE vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
CVE-2026-11914 Jul 10, 2026
Drupal Composer Vulnerability CVE-2026-11914: RCE via Composer vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
CVE-2026-11915 Jul 10, 2026
Drupal BruteForceProtection Vulnerability (CVE-2026-11915) vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
CVE-2026-15087 Jul 10, 2026
Drupal Clean RESTful: Remote Code Execution Vulnerability vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
CVE-2026-15086 Jul 10, 2026
Drupal Raw Formatter (Meta Tag Formatter) XSS via Raw Input vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
CVE-2026-15089 Jul 10, 2026
Drupal Commerce Guest Reg RCE via Directory Traversal vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.
CVE-2026-55808 Jul 10, 2026
Drupal Core XSS Vulnerability Unpatched before 10.5.12,10.6.11,11.2.14,11.3.12 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Drupal
CVE-2026-55807 Jul 10, 2026
Drupal Core SSRF vulnerability (CVE-2026-55807) affecting 0.0.0-11.3.12 Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Drupal
CVE-2026-55806 Jul 10, 2026
Drupal Core Open Redirect vulnerable 0.0.0-10.5.12/10.6.0-11.3.12 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Drupal
CVE-2026-55804 Jul 10, 2026
Drupal Core 0.0.011.3.12 OI: Improper DVA Object Modification Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Drupal
CVE-2026-55803 Jul 10, 2026
Drupal core 11.3.12 Object Injection via Attribute Modification Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Drupal
CVE-2026-15085 Jul 10, 2026
Stored XSS in Drupal AI SEO/GEO Analyzer 0.0.0-1.1.3 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.
CVE-2026-15084 Jul 10, 2026
Drupal UI Patterns 2.0.0-2.0.17 XSS (Stored) Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17.
Drupal
CVE-2026-15083 Jul 10, 2026
Drupal ECA Module Inject (0.0.02.1.20,3.0.03.0.12,3.1.03.1.4) Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.
CVE-2026-15082 Jul 10, 2026
Drupal Siteimprove Analytics XSS < 2.0.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1.
CVE-2026-15081 Jul 10, 2026
Drupal Location Selector 1.3.0 SQLI via unescaped field Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.
CVE-2026-15080 Jul 10, 2026
Drupal Ray Enterprise Translate CSRF (0.0.0-4.0.4,4.1.0-4.1.4,11.0.0-11.0.4) Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.
CVE-2026-58591 Jul 10, 2026
Drupal Colorbox XSS (v 2.2.0) Improper Input Neutralization Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.
CVE-2026-15079 Jul 10, 2026
Drupal Login Disable <=2.1.4 Brute Force via Improper Auth Restriction Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.
CVE-2026-58590 Jul 10, 2026
Drupal FlowDrop <=1.6.0 Missing Auth: Forceful Browsing (CVE-2026-58590) Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
CVE-2026-58589 Jul 10, 2026
CVE-2026-58589: Drupal FlowDrop 0.0.0-1.6.0 Missing Auth: Forceful Browsing Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
CVE-2026-58588 Jul 10, 2026
Drupal Canvas XSS before v1.7.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.
Drupal
CVE-2026-58587 Jul 10, 2026
Drupal Canvas XSS 0.0.01.4.2, 1.5.01.5.2, 1.6.01.6.1, 1.7.01.7.1 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.
Drupal
CVE-2026-13244 Jul 10, 2026
Drupal Tealium iQ TM Obj Inject (v<2.4.0) Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.
CVE-2026-13243 Jul 10, 2026
Drupal Salesforce Suite CSRF VULN (5.1.3) Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3.
CVE-2026-13242 Jul 10, 2026
Drupal Geolocation Field <=3.15.0 SQL Injection via unsanitized input Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.
CVE-2026-13241 Jul 10, 2026
Drupal Paragraphs <=1.21.0: Missing Auth Forceful Browsing Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
CVE-2026-13240 Jul 10, 2026
Drupal Paragraphs <=1.21.0 Missing Auth Enables Forceful Browsing Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
CVE-2026-13239 Jul 10, 2026
Missing Auth: WissKI 0.0.0-4.2.0 Forceful Browsing Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0.
CVE-2026-13238 Jul 10, 2026
Drupal Commerce: Realex Incorrect Auth allows Forceful Browsing (<3.0.2) Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2.
CVE-2026-13237 Jul 10, 2026
Drupal AI Agents <=1.3.1 Incorrect Auth: Forceful Browsing Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
CVE-2026-13236 Jul 10, 2026
Missing Auth in Drupal AI Agents (v0.0.01.3.1) Allows Forceful Browsing Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
CVE-2026-13235 Jul 10, 2026
Drupal AI Missing Auth v1.4.3 Forceful Browse (CVE-2026-13235) Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
Artificial Intelligence
CVE-2026-13233 Jul 10, 2026
Drupal OpenAI Provider SSRF v0.0.0-1.1.1 & 1.2.0-1.2.2 Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.
CVE-2026-13234 Jul 10, 2026
Drupal AI (0.0.01.4.3) XSS Vulnerability Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
Artificial Intelligence
CVE-2026-13232 Jul 10, 2026
Drupal admin_feedback V02.8.0 Incorrect Auth Forceful Browsing Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.
CVE-2026-13231 Jul 10, 2026
Drupal Advanced Content Feedback Stored XSS pre-2.8.0 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.
CVE-2026-55810 Jul 10, 2026
CVE-2026-55810: Object Injection in Drupal PlotlyJS Graphing <=3.0.2 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.
CVE-2026-55809 Jul 10, 2026
Drupal Flag Attendance Field <1.3: Improper Dynamic Obj Attr Mod (Obj Inj) Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.
CVE-2026-12535 Jul 10, 2026
Drupal Formatter Field <=2.0.0 Object Injection via Dynamic Attributes Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
CVE-2026-11909 Jul 10, 2026
Drupal ExamplesTM for Developers <4.0.6: Missing Auth, Forceful Browsing Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
CVE-2026-11908 Jul 10, 2026
Drupal Tagify Stored XSS before 1.2.53 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Stored XSS. This issue affects Tagify versions: from 0.0.0 to 1.2.52.
CVE-2026-10770 Jul 10, 2026
Drupal AntiSpam by CleanTalk Reflected XSS (pre9.7.2) Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.
CVE-2026-10769 Jul 10, 2026
Drupal Commerce 3.3.x Stored XSS Vulnerability Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This issue affects Commerce Core versions: from 3.3.0 to 3.3.6.
CVE-2026-10768 Jul 10, 2026
Drupal LocalGov Workflows 0.0.0-1.6.0 Missing Auth Forceful Browsing Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
CVE-2026-9726 Jul 10, 2026
Drupal AlternativeCommerce OI IMCA Obj Injection 0.0.02.1.17 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
Drupal
CVE-2026-6816 May 28, 2026
Drupal TFA Basic Plugins < 1.2 Access Bypass via Admin Users An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
CVE-2026-5343 May 28, 2026
Drupal SAML SSO SP <3.1.4 Priv Esc via Condition Check Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.
CVE-2026-4093 May 21, 2026
Drupal 7 Term Reference Tree module XSS; tokens unsanitized v7.x-1.11 In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered. Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11.
CVE-2026-4929 May 21, 2026
XSS in Drupal 7 SHS module (7.x-1.0 7.x-1.10) via term names Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context. This affects versions from 7.x-1.0 through (and including) 7.x-1.10.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.