Drupal.org maintains one of the most widely deployed open-source web content management systems, with a substantial ecosystem of contributed modules and extensions that collectively present a broadly represented vulnerability surface. The platform's exposure centers on its core CMS product and commonly adopted modules such as project issue tracking, print, aggregation, and everyblog, and recurs consistently through application-layer weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and input-validation flaws endemic to server-side web applications. As a prominent, actively maintained platform subject to coordinated community disclosure, Drupal's advisory practice and patch cycles have established it as a reference point for defenders managing large installed bases of content management infrastructure. Defenders should subscribe to Drupal's security advisories and track core and contributed-module updates as routine patches; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Drupal.org over time
Of all the CVEs published by Drupal.org as a CNA, 23.4% affect products that Drupal.org develops as a vendor.
Of all the CVEs published that affect products developed by Drupal.org, 9.8% are self-published by Drupal.org as a CNA.
Signals from CVEs in this vendor scope (866 CVEs).
866 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9082CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from | May 20, 2026 | 9.8 | 99 | YES | YES |
CVE-2018-7600CRITICAL Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems | Mar 29, 2018 | 9.8 | 99 | YES | YES |
CVE-2019-6340HIGH Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in | Feb 21, 2019 | 8.1 | 98 | YES | YES |
CVE-2018-7602CRITICAL A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site | Jul 19, 2018 | 9.8 | 98 | YES | YES |
CVE-2020-28949HIGH Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succe | Nov 19, 2020 | 7.8 | 95 | YES | YES |
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2020-36193HIGH Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. | Jan 18, 2021 | 7.5 | 91 | YES | NO |
CVE-2014-3704HIGH The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduc | Oct 16, 2014 | 7.5 | 91 | NO | YES |
CVE-2020-11022MEDIUM In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append | Apr 29, 2020 | 6.1 | 83 | NO | YES |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
Signals from CVEs in this vendor scope (866 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drupal.org.
Media articles that mention a CVE ID that affects a product developed by Drupal.org — matched by CVE ID, not by vendor name.