Drupal Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Drupal products.
Products
- Drupal Core49 vulnerabilities
- Core21 vulnerabilities
- AI (Artificial Intelligence)8 vulnerabilities
- Open Social8 vulnerabilities
- Enterprise MFA - TFA for Drupal6 vulnerabilities
- COOKiES Consent Management4 vulnerabilities
- Drupal4 vulnerabilities
- Drupal Canvas4 vulnerabilities
- Two-factor Authentication (TFA)4 vulnerabilities
- Authenticator Login3 vulnerabilities
- Facets3 vulnerabilities
- Login Disable3 vulnerabilities
- One Time Password3 vulnerabilities
- OpenID Connect / OAuth client3 vulnerabilities
- Tagify3 vulnerabilities
- Access code2 vulnerabilities
- Acquia DAM2 vulnerabilities
- Advanced Content Feedback (aka admin_feedback)2 vulnerabilities
- AI Agents2 vulnerabilities
- Anti-Spam by CleanTalk2 vulnerabilities
- CivicTheme Design System2 vulnerabilities
- Colorbox2 vulnerabilities
- Data-module2 vulnerabilities
- drupal_core2 vulnerabilities
- ECA: Event - Condition - Action2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-11913CRITICAL | Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. CWE-79Jul 10, 2026 | CVSS9.8v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11914MEDIUM | Composer - Critical - Unsupported - SA-CONTRIB-2026-046vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. CWE-20Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11915MEDIUM | Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. CWE-307Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.192% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15087MEDIUM | Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. CWE-287Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.244% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15086MEDIUM | Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15089CRITICAL | Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. CWE-287Jul 10, 2026 | CVSS9.1v3.1 | EPSS0.298% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55808MEDIUM | Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. CWE-79Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. CWE-918Jul 10, 2026 | CVSS3.1v3.1 | EPSS0.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-55806MEDIUM | Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. CWE-601Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.206% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55804MEDIUM | Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. CWE-915Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55803MEDIUM | Drupal core - Critical - PHP object injection - SA-CORE-2026-005Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. CWE-915Jul 10, 2026 | CVSS5.9v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15085MEDIUM | AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3. CWE-79Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.165% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15084MEDIUM | UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17. CWE-79Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.165% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15083MEDIUM | ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4. CWE-915Jul 10, 2026 | CVSS4.2v3.1 | EPSS0.179% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15082MEDIUM | Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affects Siteimprove Analytics versions: from 0.0.0 to 2.0.1. CWE-79Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.165% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15081HIGH | Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0. CWE-89Jul 10, 2026 | CVSS7.4v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15080MEDIUM | Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4. CWE-352Jul 10, 2026 | CVSS4.3v3.1 | EPSS0.118% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15079MEDIUM | Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4. CWE-307Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58591MEDIUM | Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0. CWE-79Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.136% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58590MEDIUM | FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. CWE-862Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58589MEDIUM | FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. CWE-862Jul 10, 2026 | CVSS5.4v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58588MEDIUM | Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. CWE-79Jul 10, 2026 | CVSS6.1v3.1 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58587MEDIUM | Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. CWE-79Jul 10, 2026 | CVSS6.1v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13244HIGH | Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0. CWE-915Jul 10, 2026 | CVSS8.1v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13243MEDIUM | Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. CWE-352Jul 10, 2026 | CVSS4.8v3.1 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |