📦 Drupal

by Drupal

🔍 What is Drupal?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-55636

CRITICAL CVSS 9.8 Dec 10, 2024

This CVE describes a gadget chain vulnerability in Drupal Core that enables object injection when untrusted data is deserialized. While not directly exploitable on its own, it provides a vector for re...

CVE-2024-55638

CRITICAL CVSS 9.8 Dec 10, 2024

This CVE describes a gadget chain in Drupal Core that enables object injection when untrusted data is deserialized. While the chain itself isn't directly exploitable, it can be leveraged for remote co...

CVE-2020-13675

CRITICAL CVSS 9.8 Feb 11, 2022

CVE-2020-13675 is a critical access bypass vulnerability in Drupal's JSON:API and REST/File modules that allows attackers to upload files without proper validation. This affects Drupal sites using the...

CVE-2020-13665

CRITICAL CVSS 9.8 May 5, 2021

This vulnerability allows attackers to bypass access controls in Drupal Core's JSON:API module when configured in read/write mode. Attackers could potentially perform unauthorized operations like crea...

CVE-2025-31674

HIGH CVSS 7.5 Mar 31, 2025

This CVE describes an object injection vulnerability in Drupal core that allows attackers to modify dynamically-determined object attributes improperly. Attackers could potentially execute arbitrary c...

CVE-2024-55634

HIGH CVSS 8.1 Dec 10, 2024

This vulnerability in Drupal Core allows attackers to escalate privileges, potentially gaining administrative access to Drupal sites. It affects Drupal installations running vulnerable versions from 8...

CVE-2024-11941

HIGH CVSS 7.5 Dec 5, 2024

A denial-of-service vulnerability in Drupal Core allows attackers to cause excessive resource allocation through specially crafted requests. This affects Drupal sites running versions 10.2.0-10.2.1 an...

CVE-2024-22362

HIGH CVSS 7.5 Jan 16, 2024

This CVE describes a vulnerability in Drupal's handling of structural elements that could allow an attacker to trigger a denial-of-service condition. The vulnerability affects Drupal core installation...

CVE-2023-5256

HIGH CVSS 7.5 Sep 28, 2023

Drupal's JSON:API module can expose sensitive error backtraces that may be cached and accessible to anonymous users. This information disclosure vulnerability could lead to privilege escalation by rev...

CVE-2022-25277

HIGH CVSS 7.2 Apr 26, 2023

This vulnerability allows attackers to bypass Drupal's filename sanitization when .htaccess files are explicitly allowed for upload, potentially leading to remote code execution on Apache servers. It ...

CVE-2022-25273

HIGH CVSS 7.5 Apr 26, 2023

This vulnerability in Drupal's form API allows attackers to bypass input validation on certain contributed or custom module forms. Attackers could inject disallowed values or overwrite data, potential...

CVE-2022-25275

HIGH CVSS 7.5 Apr 26, 2023

This vulnerability allows unauthorized access to image files stored in non-standard file systems when insecure derivatives are enabled. It affects Drupal sites using contributed modules that implement...

CVE-2022-31042

HIGH CVSS 7.5 Jun 10, 2022

Guzzle HTTP client versions before 6.5.7 and 7.4.4 expose sensitive cookie information during HTTP redirects. When a request to an HTTPS server redirects to HTTP or to a different host, manually added...

CVE-2022-29248

HIGH CVSS 8.0 May 25, 2022

Guzzle PHP HTTP client versions prior to 6.5.6 and 7.4.3 have a cookie domain validation vulnerability that allows malicious servers to set cookies for unrelated domains. Only applications that manual...

CVE-2022-25271

HIGH CVSS 7.5 Feb 16, 2022

This vulnerability in Drupal core's form API allows improper input validation in certain contributed or custom module forms. Attackers could inject disallowed values or overwrite data, potentially alt...

CVE-2020-13670

HIGH CVSS 7.5 Feb 11, 2022

This vulnerability allows attackers to access metadata of private files in Drupal by guessing file IDs, potentially exposing sensitive information. It affects Drupal Core versions 8.8.x before 8.8.10,...

CVE-2020-13677

HIGH CVSS 7.5 Feb 11, 2022

CVE-2020-13677 is an access control vulnerability in Drupal's JSON:API module that allows attackers to bypass intended content restrictions. This affects Drupal sites with the JSON:API module enabled,...

CVE-2020-13664

HIGH CVSS 8.8 May 5, 2021

This CVE describes an arbitrary PHP code execution vulnerability in Drupal Core that allows attackers to create specially named directories on the file system. When combined with brute force technique...

CVE-2025-13082

MEDIUM CVSS 4.3 Nov 18, 2025

This CVE describes a UI misrepresentation vulnerability in Drupal core that allows content spoofing. Attackers can manipulate the user interface to display misleading information, potentially tricking...

CVE-2025-13080

MEDIUM CVSS 5.3 Nov 18, 2025

This vulnerability in Drupal core allows attackers to bypass access controls through forceful browsing, potentially accessing restricted content or functionality. It affects Drupal sites running vulne...

CVE-2025-13081

MEDIUM CVSS 5.9 Nov 18, 2025

This CVE describes an object injection vulnerability in Drupal core that allows attackers to modify dynamically-determined object attributes improperly. It affects Drupal sites running vulnerable vers...

CVE-2025-3057

MEDIUM CVSS 6.1 Mar 31, 2025

This Cross-Site Scripting (XSS) vulnerability in Drupal core allows attackers to inject malicious scripts into web pages viewed by other users. It affects Drupal installations running vulnerable versi...

CVE-2025-31675

MEDIUM CVSS 5.4 Mar 31, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Drupal core that allows attackers to inject malicious scripts into web pages. The vulnerability affects Drupal installations running af...

CVE-2025-31673

MEDIUM CVSS 4.6 Mar 31, 2025

This CVE describes an incorrect authorization vulnerability in Drupal core that allows forceful browsing (accessing restricted pages without proper permissions). It affects Drupal sites running vulner...

CVE-2024-12393

MEDIUM CVSS 5.4 Dec 10, 2024

This Cross-Site Scripting (XSS) vulnerability in Drupal Core allows attackers to inject malicious scripts into web pages viewed by other users. It affects Drupal sites running versions 8.8.0 through 1...

CVE-2024-45440

MEDIUM CVSS 5.3 Aug 29, 2024

This vulnerability in Drupal 11.x-dev allows Full Path Disclosure when the hash_salt configuration points to a non-existent file. Attackers can exploit this to reveal the server's full filesystem path...

CVE-2025-13083

LOW CVSS 3.7 Nov 18, 2025

This vulnerability in Drupal core allows attackers to exploit web browser caching to access sensitive information that should be protected. It affects Drupal sites with misconfigured access controls, ...