All 55 CVE vulnerabilities found in Drupal core, with AI-generated Chinese analysis, references, and POCs.
This page aggregates vulnerability data for Drupal core, focusing on security weaknesses identified within the primary content management system software. It serves as a central repository for tracking security issues related to the core codebase maintained by the Drupal community. The content collected here encompasses a wide range of vulnerability types, including Cross-Site Scripting (XSS), SQL Injection, Denial of Service, and improper access control issues. The timeline covered spans from the early releases of Drupal 7 and 8 through to the most recent versions, ensuring comprehensive historical context. This approach allows users to see how certain weakness classes have evolved or persisted across different major releases and security updates over the years. Visitors to this page can discover detailed information by tracking vendor advisories issued by the Drupal Security Team, understanding the characteristics and exploitation vectors of specific weakness classes, and looking up a product’s vulnerability history to assess risk exposure. The data is organized to facilitate efficient analysis of security trends and to help developers prioritize remediation efforts. By providing a structured view of past and present security incidents, this resource supports informed decision-making for system administrators and security analysts responsible for maintaining Drupal core installations. The information presented is derived from official security advisories and verified reports, ensuring accuracy and reliability for those seeking to strengthen their Drupal deployments against known threats.
Vendor: drupal core
All 55 known CVE vulnerabilities affecting Drupal core with full Chinese analysis, references, and POCs where available.