Drupal Security Vulnerabilities (CVEs)
Track 31 security vulnerabilities affecting Drupal products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This CVE describes a UI misrepresentation vulnerability in Drupal core that allows content spoofing. Attackers can manipulate the user interface to di...
Nov 18, 2025This vulnerability in Drupal core allows attackers to exploit web browser caching to access sensitive information that should be protected. It affects...
Nov 18, 2025This vulnerability in Drupal core allows attackers to bypass access controls through forceful browsing, potentially accessing restricted content or fu...
Nov 18, 2025This CVE describes an object injection vulnerability in Drupal core that allows attackers to modify dynamically-determined object attributes improperl...
Nov 18, 2025This vulnerability allows attackers to inject malicious scripts into web pages generated by Drupal COOKiES Consent Management module, which could exec...
Jun 13, 2025This CVE describes a missing authentication vulnerability in Drupal Panels that allows attackers to bypass access controls on critical functions. Atta...
Apr 9, 2025This Cross-Site Scripting (XSS) vulnerability in Drupal core allows attackers to inject malicious scripts into web pages viewed by other users. It aff...
Mar 31, 2025This OS command injection vulnerability in Drupal AI allows attackers to execute arbitrary operating system commands on the server. It affects Drupal ...
Mar 31, 2025This CVE describes a cross-site scripting (XSS) vulnerability in Drupal core that allows attackers to inject malicious scripts into web pages. The vul...
Mar 31, 2025This CVE describes an incorrect authorization vulnerability in Drupal core that allows forceful browsing (accessing restricted pages without proper pe...
Mar 31, 2025This CVE describes an object injection vulnerability in Drupal core that allows attackers to modify dynamically-determined object attributes improperl...
Mar 31, 2025This Cross-Site Scripting (XSS) vulnerability in Drupal Core allows attackers to inject malicious scripts into web pages viewed by other users. It aff...
Dec 10, 2024This vulnerability in Drupal Core allows attackers to escalate privileges, potentially gaining administrative access to Drupal sites. It affects Drupa...
Dec 10, 2024This CVE describes a gadget chain vulnerability in Drupal Core that enables object injection when untrusted data is deserialized. While not directly e...
Dec 10, 2024This CVE describes a gadget chain in Drupal Core that enables object injection when untrusted data is deserialized. While the chain itself isn't direc...
Dec 10, 2024A denial-of-service vulnerability in Drupal Core allows attackers to cause excessive resource allocation through specially crafted requests. This affe...
Dec 5, 2024This vulnerability in Drupal 11.x-dev allows Full Path Disclosure when the hash_salt configuration points to a non-existent file. Attackers can exploi...
Aug 29, 2024This CVE describes a vulnerability in Drupal's handling of structural elements that could allow an attacker to trigger a denial-of-service condition. ...
Jan 16, 2024Drupal's JSON:API module can expose sensitive error backtraces that may be cached and accessible to anonymous users. This information disclosure vulne...
Sep 28, 2023This vulnerability allows attackers to bypass Drupal's filename sanitization when .htaccess files are explicitly allowed for upload, potentially leadi...
Apr 26, 2023This vulnerability in Drupal's form API allows attackers to bypass input validation on certain contributed or custom module forms. Attackers could inj...
Apr 26, 2023This vulnerability allows unauthorized access to image files stored in non-standard file systems when insecure derivatives are enabled. It affects Dru...
Apr 26, 2023Guzzle HTTP client versions before 6.5.7 and 7.4.4 expose sensitive cookie information during HTTP redirects. When a request to an HTTPS server redire...
Jun 10, 2022This vulnerability allows attackers to bypass authentication and authorization in miniOrange Drupal SAML SP modules by removing SAML assertion signatu...
Jun 3, 2022Guzzle PHP HTTP client versions prior to 6.5.6 and 7.4.3 have a cookie domain validation vulnerability that allows malicious servers to set cookies fo...
May 25, 2022This vulnerability in Drupal core's form API allows improper input validation in certain contributed or custom module forms. Attackers could inject di...
Feb 16, 2022This vulnerability allows attackers to access metadata of private files in Drupal by guessing file IDs, potentially exposing sensitive information. It...
Feb 11, 2022CVE-2020-13675 is a critical access bypass vulnerability in Drupal's JSON:API and REST/File modules that allows attackers to upload files without prop...
Feb 11, 2022CVE-2020-13677 is an access control vulnerability in Drupal's JSON:API module that allows attackers to bypass intended content restrictions. This affe...
Feb 11, 2022This CVE describes an arbitrary PHP code execution vulnerability in Drupal Core that allows attackers to create specially named directories on the fil...
May 5, 2021This vulnerability allows attackers to bypass access controls in Drupal Core's JSON:API module when configured in read/write mode. Attackers could pot...
May 5, 2021Why Monitor Drupal Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 31+ known vulnerabilities affecting Drupal products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Drupal packages in under 60 seconds. No agents required - completely agentless scanning that works across Drupal deployments.
Free vulnerability database: Access detailed information about every Drupal CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Drupal CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions