Drupal Canvas Project maintains a learning-management system product that serves educational institutions, with a vulnerability profile centered on authorization and request-handling issues such as incorrect authorization decisions and server-side request forgery. The recurring weakness classes reflect the web-application architecture and integration scope typical of platforms that manage user roles, content access, and external service interactions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Drupal Canvas Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58588MEDIUM Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Dru | Jul 10, 2026 | 6.1 | 29 | NO | NO |
CVE-2026-58587MEDIUM Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Dru | Jul 10, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-3216MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1. | Mar 25, 2026 | 5.0 | 20 | NO | NO |
CVE-2026-1553MEDIUM Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4. | Feb 4, 2026 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drupal Canvas Project.
Media articles that mention a CVE ID that affects a product developed by Drupal Canvas Project — matched by CVE ID, not by vendor name.