Drupal.org

First CVE: Mar 16, 2017Active for: 9 years
364
CVEs Published
More CVEs Published than 85% of tracked CNAs
36.4
Avg CVEs / Year
More Avg CVEs / Year than 79% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
1.4%
In CISA KEV
Higher KEV Rate than 89% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Drupal.org as a CNA, 23.4% affect products that Drupal.org develops as a vendor.

23.4%
76.6%
Self-reported: 85Third-party: 279

Of all the CVEs published that affect products developed by Drupal.org, 9.8% are self-published by Drupal.org as a CNA.

90.2%
Self-published: 85Published by other CNAs: 781

Trends Over Time

The number and severity of CVEs published by Drupal.org over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2017
9 years ago
Most Recent CVE
Jul 10, 2026
14 days ago

Top CVEs

All CVEs published by Drupal.org as a CNA, regardless of affected vendor or product.

364 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from
May 20, 20269.899YESYES
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems
Mar 29, 20189.899YESYES
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in
Feb 21, 20198.198YESYES
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site
Jul 19, 20189.898YESYES
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type o
Nov 20, 20208.867YESNO
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when pe
Jan 22, 20199.847NONO
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.
Aug 6, 20189.841NONO
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
Jul 10, 20269.840NONO
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.
May 19, 20269.839NONO
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.
Aug 29, 20245.339NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA364 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network364 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low296 (81.3%)
High68 (18.7%)
Unknown0 (0.0%)
User Interaction
None221 (60.7%)
Unknown0 (0.0%)
Required143 (39.3%)
Privileges Required
Low83 (22.8%)
High41 (11.3%)
None240 (65.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (364 CVEs).

CISA KEV
5 CVEs
1.4% of CVEs· 89th percentile
Metasploit
2 CVEs
0.5% of CVEs· 83rd percentile
Nuclei
5 CVEs
1.4% of CVEs· 82nd percentile
ExploitDB
5 CVEs
1.4% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Drupal.org as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Drupal.org as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs