Drupal.org
First CVE: Mar 16, 2017Active for: 9 years
364
CVEs Published
More CVEs Published than 85% of tracked CNAs
36.4
Avg CVEs / Year
More Avg CVEs / Year than 79% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
1.4%
In CISA KEV
Higher KEV Rate than 89% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Drupal.org as a CNA, 23.4% affect products that Drupal.org develops as a vendor.
23.4%
76.6%
Self-reported: 85Third-party: 279
Of all the CVEs published that affect products developed by Drupal.org, 9.8% are self-published by Drupal.org as a CNA.
90.2%
Self-published: 85Published by other CNAs: 781
Trends Over Time
The number and severity of CVEs published by Drupal.org over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2017
9 years ago
Most Recent CVE
Jul 10, 2026
14 days ago
Top CVEs
All CVEs published by Drupal.org as a CNA, regardless of affected vendor or product.
364 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9082CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from | May 20, 2026 | 9.8 | 99 | YES | YES |
CVE-2018-7600CRITICAL Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems | Mar 29, 2018 | 9.8 | 99 | YES | YES |
CVE-2019-6340HIGH Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in | Feb 21, 2019 | 8.1 | 98 | YES | YES |
CVE-2018-7602CRITICAL A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site | Jul 19, 2018 | 9.8 | 98 | YES | YES |
CVE-2020-13671HIGH Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type o | Nov 20, 2020 | 8.8 | 67 | YES | NO |
CVE-2019-6339CRITICAL In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when pe | Jan 22, 2019 | 9.8 | 47 | NO | NO |
CVE-2017-6920CRITICAL Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations. | Aug 6, 2018 | 9.8 | 41 | NO | NO |
CVE-2026-11913CRITICAL vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. | Jul 10, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-8495CRITICAL Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.
This issue affects Date iCal: from 0.0.0 before 4.0.15. | May 19, 2026 | 9.8 | 39 | NO | NO |
CVE-2024-45440MEDIUM core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist. | Aug 29, 2024 | 5.3 | 39 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA364 CVEs
64%
23%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network364 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low296 (81.3%)
High68 (18.7%)
Unknown0 (0.0%)
User Interaction
None221 (60.7%)
Unknown0 (0.0%)
Required143 (39.3%)
Privileges Required
Low83 (22.8%)
High41 (11.3%)
None240 (65.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (364 CVEs).
CISA KEV
5 CVEs
1.4% of CVEs· 89th percentile
Metasploit
2 CVEs
0.5% of CVEs· 83rd percentile
Nuclei
5 CVEs
1.4% of CVEs· 82nd percentile
ExploitDB
5 CVEs
1.4% of CVEs· 84th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Drupal.org as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Drupal.org as a CNA — matched by CVE ID, not by organization name.