Drupal Core
Drupal- Product type
- Other
- Catalog vulnerabilities
- 49
Severity across 49 analyzed records
en
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, Drupal Core has 8 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Drupal Core and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-15916Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010 | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityMedium |
CVE-2026-15917Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011 | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityMedium |
CVE-2026-55805Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012 | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityMedium |
CVE-2026-55808Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009 | Exploitation statusNot known exploited | FixYes | Published07/10/2026 | SeverityMedium |
CVE-2026-55807Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008 | Exploitation statusNot known exploited | FixYes | Published07/10/2026 | SeverityLow |
CVE-2026-55806Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007 | Exploitation statusNot known exploited | FixYes | Published07/10/2026 | SeverityMedium |
CVE-2026-55804Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006 | Exploitation statusNot known exploited | FixYes | Published07/10/2026 | SeverityMedium |
CVE-2026-55803Drupal core - Critical - PHP object injection - SA-CORE-2026-005 | Exploitation statusNot known exploited | FixYes | Published07/10/2026 | SeverityMedium |
CVE-2026-9082Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 | Exploitation statusKEV | FixYes | Published05/20/2026 | SeverityCritical |
CVE-2026-6367Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003 | Exploitation statusNot known exploited | FixYes | Published05/19/2026 | SeverityMedium |
CVE-2026-6366Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 | Exploitation statusNot known exploited | FixYes | Published05/19/2026 | SeverityMedium |
CVE-2026-6365Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 | Exploitation statusNot known exploited | FixYes | Published05/19/2026 | SeverityMedium |
CVE-2025-13083Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 | Exploitation statusNot known exploited | FixYes | Published11/18/2025 | SeverityLow |
CVE-2025-13082Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 | Exploitation statusNot known exploited | FixYes | Published11/18/2025 | SeverityMedium |
CVE-2025-13081Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 | Exploitation statusNot known exploited | FixYes | Published11/18/2025 | SeverityMedium |
CVE-2025-13080Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 | Exploitation statusNot known exploited | FixYes | Published11/18/2025 | SeverityMedium |
CVE-2025-31675Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 | Exploitation statusNot known exploited | FixYes | Published03/31/2025 | SeverityMedium |
CVE-2025-31674Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 | Exploitation statusNot known exploited | FixYes | Published03/31/2025 | SeverityHigh |
CVE-2025-31673Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 | Exploitation statusNot known exploited | FixYes | Published03/31/2025 | SeverityMedium |
CVE-2025-3057Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 | Exploitation statusNot known exploited | FixYes | Published03/31/2025 | SeverityMedium |
CVE-2024-55638Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008 | Exploitation statusNot known exploited | FixYes | Published12/09/2024 | SeverityCritical |
CVE-2024-55637Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007 | Exploitation statusNot known exploited | FixYes | Published12/09/2024 | SeverityCritical |
CVE-2024-55636Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 | Exploitation statusNot known exploited | FixYes | Published12/09/2024 | SeverityCritical |
CVE-2024-55635Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005 | Exploitation statusNot known exploited | FixYes | Published12/09/2024 | SeverityMedium |
CVE-2024-55634Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004 | Exploitation statusNot known exploited | FixYes | Published12/09/2024 | SeverityHigh |
CVE-2024-12393Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003 | Exploitation statusNot known exploited | FixYes | Published12/09/2024 | SeverityMedium |
CVE-2024-11942Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002 | Exploitation statusNot known exploited | FixYes | Published12/05/2024 | SeverityMedium |
CVE-2024-11941Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001 | Exploitation statusNot known exploited | FixYes | Published12/05/2024 | SeverityHigh |
CVE-2024-45440 | Exploitation statusNot known exploited | FixNot confirmed | Published08/29/2024 | SeverityMedium |
CVE-2020-13688 | Exploitation statusNot confirmed | FixYes | Published06/11/2021 | SeverityUnknown |
CVE-2020-13663 | Exploitation statusNot confirmed | FixYes | Published06/11/2021 | SeverityUnknown |
CVE-2020-13667 | Exploitation statusNot confirmed | FixYes | Published05/17/2021 | SeverityUnknown |
CVE-2020-13664 | Exploitation statusNot confirmed | FixYes | Published05/05/2021 | SeverityUnknown |
CVE-2020-13662 | Exploitation statusNot confirmed | FixNot confirmed | Published05/05/2021 | SeverityUnknown |
CVE-2020-13665 | Exploitation statusNot confirmed | FixYes | Published05/05/2021 | SeverityUnknown |
CVE-2020-13666 | Exploitation statusNot confirmed | FixYes | Published05/05/2021 | SeverityUnknown |
CVE-2020-13671 | Exploitation statusKEV | FixNot confirmed | Published11/20/2020 | SeverityHigh |
CVE-2019-6342Drupal core - Critical - Access bypass - SA-CORE-2019-008 | Exploitation statusNot confirmed | FixNot confirmed | Published05/28/2020 | SeverityUnknown |
CVE-2019-6341Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004 | Exploitation statusNot confirmed | FixYes | Published03/26/2019 | SeverityUnknown |
CVE-2019-6340Drupal core - Highly critical - Remote Code Execution | Exploitation statusKEV | FixYes | Published02/21/2019 | SeverityHigh |
CVE-2017-6923Access bypass in Drupal 8 views | Exploitation statusNot confirmed | FixYes | Published01/22/2019 | SeverityUnknown |
CVE-2019-6338third-party PEAR Archive_Tar library updates | Exploitation statusNot confirmed | FixYes | Published01/22/2019 | SeverityUnknown |
CVE-2017-6922Files uploaded by anonymous users into a private file system can be accessed by other anonymous users | Exploitation statusNot confirmed | FixYes | Published01/22/2019 | SeverityUnknown |
CVE-2019-6339PHAR stream wrapper Arbitrary PHP code execution | Exploitation statusNot confirmed | FixYes | Published01/22/2019 | SeverityUnknown |
CVE-2017-6921File REST resource does not properly validate | Exploitation statusNot confirmed | FixYes | Published01/15/2019 | SeverityUnknown |
CVE-2017-6924REST API can bypass comment approval - Access Bypass - Moderately Critical | Exploitation statusNot confirmed | FixYes | Published01/15/2019 | SeverityUnknown |
CVE-2017-6377 | Exploitation statusNot confirmed | FixNot confirmed | Published03/16/2017 | SeverityUnknown |
CVE-2017-6379 | Exploitation statusNot confirmed | FixNot confirmed | Published03/16/2017 | SeverityUnknown |
CVE-2017-6381 | Exploitation statusNot confirmed | FixNot confirmed | Published03/16/2017 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan