Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Drupal core — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in Drupal core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Drupal core, focusing on security weaknesses identified within the primary content management system software. It serves as a central repository for tracking security issues related to the core codebase maintained by the Drupal community. The content collected here encompasses a wide range of vulnerability types, including Cross-Site Scripting (XSS), SQL Injection, Denial of Service, and improper access control issues. The timeline covered spans from the early releases of Drupal 7 and 8 through to the most recent versions, ensuring comprehensive historical context. This approach allows users to see how certain weakness classes have evolved or persisted across different major releases and security updates over the years. Visitors to this page can discover detailed information by tracking vendor advisories issued by the Drupal Security Team, understanding the characteristics and exploitation vectors of specific weakness classes, and looking up a product’s vulnerability history to assess risk exposure. The data is organized to facilitate efficient analysis of security trends and to help developers prioritize remediation efforts. By providing a structured view of past and present security incidents, this resource supports informed decision-making for system administrators and security analysts responsible for maintaining Drupal core installations. The information presented is derived from official security advisories and verified reports, ensuring accuracy and reliability for those seeking to strengthen their Drupal deployments against known threats.

Vendor: drupal core

CVE IDTitleCVSSSeverityPublished
CVE-2020-13662 IBM API Connect 输入验证错误漏洞 6.1 -2021-05-05
CVE-2020-13665 Drupal 安全漏洞 9.8 -2021-05-05
CVE-2020-13666 Drupal 跨站脚本漏洞 6.1 -2021-05-05
CVE-2020-13671 Drupal core 代码问题漏洞 8.8 -2020-11-20
CVE-2019-6342 Drupal core - Critical - Access bypass - SA-CORE-2019-008 7.5 -2020-05-28
CVE-2011-2726 Drupal 安全漏洞 7.5 -2019-11-15
CVE-2019-6341 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004 5.4 -2019-03-26
CVE-2019-6340 Drupal core - Highly critical - Remote Code Execution 8.1 -2019-02-21
CVE-2017-6923 Access bypass in Drupal 8 views 6.5 -2019-01-22
CVE-2019-6339 PHAR stream wrapper Arbitrary PHP code execution 9.8 -2019-01-22
CVE-2019-6338 third-party PEAR Archive_Tar library updates 8.0 -2019-01-22
CVE-2017-6922 Files uploaded by anonymous users into a private file system can be accessed by other anonymous users 7.5 -2019-01-22
CVE-2017-6921 File REST resource does not properly validate 7.4 -2019-01-15
CVE-2017-6924 REST API can bypass comment approval - Access Bypass - Moderately Critical 7.4 -2019-01-15
CVE-2017-6920 Drupal 安全漏洞 9.8 -2018-08-06
CVE-2017-6928 Drupal core 安全漏洞 5.3 -2018-03-01
CVE-2017-6926 Drupal 安全漏洞 8.1 -2018-03-01
CVE-2017-6927 Drupal 跨站脚本漏洞 6.1 -2018-03-01
CVE-2017-6929 Drupal jQuery 跨站脚本漏洞 6.1 -2018-03-01
CVE-2017-6930 Drupal 安全漏洞 8.1 -2018-03-01
CVE-2017-6931 Drupal Settings Tray模块安全漏洞 6.5 -2018-03-01
CVE-2017-6932 Drupal core 安全漏洞 4.7 -2018-03-01
CVE-2017-6381 Drupal 安全漏洞 8.1 -2017-03-16
CVE-2017-6379 Drupal 跨站请求伪造漏洞 7.5 -2017-03-16
CVE-2017-6377 Drupal 安全漏洞 9.1 -2017-03-16

All 55 known CVE vulnerabilities affecting Drupal core with full Chinese analysis, references, and POCs where available.