Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Drupal.org

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 866
47.3
VTI Score
High

Drupal.org maintains one of the most widely deployed open-source web content management systems, with a substantial ecosystem of contributed modules and extensions that collectively present a broadly represented vulnerability surface. The platform's exposure centers on its core CMS product and commonly adopted modules such as project issue tracking, print, aggregation, and everyblog, and recurs consistently through application-layer weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and input-validation flaws endemic to server-side web applications. As a prominent, actively maintained platform subject to coordinated community disclosure, Drupal's advisory practice and patch cycles have established it as a reference point for defenders managing large installed bases of content management infrastructure. Defenders should subscribe to Drupal's security advisories and track core and contributed-module updates as routine patches; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
866
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
5.1
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Drupal.org over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jul 10, 2026
14 days ago

Self-Reporting Analysis

Of all the CVEs published by Drupal.org as a CNA, 23.4% affect products that Drupal.org develops as a vendor.

23.4%
76.6%
Self-reported: 85 (23.4%)
Third-party: 279 (76.6%)

Of all the CVEs published that affect products developed by Drupal.org, 9.8% are self-published by Drupal.org as a CNA.

90.2%
Self-published: 85 (9.8%)
Other CNAs: 781 (90.2%)

Products(142 total)

Top CVEs

Signals from CVEs in this vendor scope (866 CVEs).

866 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-9082CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from
May 20, 20269.899YESYES
CVE-2018-7600CRITICAL
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems
Mar 29, 20189.899YESYES
CVE-2019-6340HIGH
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in
Feb 21, 20198.198YESYES
CVE-2018-7602CRITICAL
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site
Jul 19, 20189.898YESYES
CVE-2020-28949HIGH
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succe
Nov 19, 20207.895YESYES
CVE-2020-11023MEDIUM
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
CVE-2020-36193HIGH
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Jan 18, 20217.591YESNO
CVE-2014-3704HIGH
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduc
Oct 16, 20147.591NOYES
CVE-2020-11022MEDIUM
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
CVE-2019-11358MEDIUM
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
View all 866 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products866 CVEs
24%
59%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (0.2%)
Network155 (17.9%)
Unknown709 (81.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low132 (15.2%)
High25 (2.9%)
Unknown709 (81.9%)
User Interaction
None90 (10.4%)
Unknown709 (81.9%)
Required67 (7.7%)
Privileges Required
Low39 (4.5%)
High10 (1.2%)
None108 (12.5%)
Unknown709 (81.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (866 CVEs).

CISA KEV
8 CVEs
0.9% of CVEs· 99th percentile
Metasploit
8 CVEs
0.9% of CVEs· 97th percentile
Nuclei
8 CVEs
0.9% of CVEs· 95th percentile
ExploitDB
20 CVEs
2.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Drupal.org.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Drupal.org — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Drupal.org's Products

View all 7 CNAs →

Top CWEs