Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

drupal core — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in drupal core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Drupal core, focusing on security weaknesses identified within the primary content management system software. It serves as a central repository for tracking security issues related to the core codebase maintained by the Drupal community. The content collected here encompasses a wide range of vulnerability types, including Cross-Site Scripting (XSS), SQL Injection, Denial of Service, and improper access control issues. The timeline covered spans from the early releases of Drupal 7 and 8 through to the most recent versions, ensuring comprehensive historical context. This approach allows users to see how certain weakness classes have evolved or persisted across different major releases and security updates over the years. Visitors to this page can discover detailed information by tracking vendor advisories issued by the Drupal Security Team, understanding the characteristics and exploitation vectors of specific weakness classes, and looking up a product’s vulnerability history to assess risk exposure. The data is organized to facilitate efficient analysis of security trends and to help developers prioritize remediation efforts. By providing a structured view of past and present security incidents, this resource supports informed decision-making for system administrators and security analysts responsible for maintaining Drupal core installations. The information presented is derived from official security advisories and verified reports, ensuring accuracy and reliability for those seeking to strengthen their Drupal deployments against known threats.

Vendor: drupal core

CVE IDTitleCVSSSeverityPublished
CVE-2026-55808 Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009 CWE-79--2026-07-10
CVE-2026-55807 Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008 CWE-918--2026-07-10
CVE-2026-55806 Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007 CWE-601--2026-07-10
CVE-2026-55804 Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006 CWE-915--2026-07-10
CVE-2026-55803 Drupal core - Critical - PHP object injection - SA-CORE-2026-005 CWE-915--2026-07-10
CVE-2026-9082 Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 CWE-89 9.8 Critical2026-05-20
CVE-2026-6367 Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003 CWE-79--2026-05-19
CVE-2026-6366 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 CWE-915--2026-05-19
CVE-2026-6365 Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 CWE-79--2026-05-19
CVE-2025-13083 Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 CWE-525 7.5AIHighAI2025-11-18
CVE-2025-13082 Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 CWE-451 4.3AIMediumAI2025-11-18
CVE-2025-13081 Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 CWE-915 9.8AICriticalAI2025-11-18
CVE-2025-13080 Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 CWE-754--AI2025-11-18
CVE-2025-31675 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 CWE-79 6.1 -2025-03-31
CVE-2025-31674 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 CWE-915 9.8 -2025-03-31
CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 CWE-863 6.5 -2025-03-31
CVE-2025-3057 Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 CWE-79 6.1 -2025-03-31
CVE-2024-55638 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008 CWE-915 9.8 -2024-12-09
CVE-2024-55637 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007 CWE-915 9.8 -2024-12-09
CVE-2024-55636 Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 CWE-915 9.8 -2024-12-09
CVE-2024-55635 Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005 CWE-79 6.1 -2024-12-09
CVE-2024-55634 Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004 CWE-178 8.8 -2024-12-09
CVE-2024-12393 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003 CWE-79 6.1 -2024-12-09
CVE-2024-11942 Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002 CWE-390 9.1 -2024-12-05
CVE-2024-11941 Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001 CWE-835 7.5 -2024-12-05
CVE-2024-45440 Drupal 安全漏洞 5.3AIMediumAI2024-08-29
CVE-2020-13688 Drupal Core 跨站脚本漏洞 6.1 -2021-06-11
CVE-2020-13663 Drupal 跨站请求伪造漏洞 8.8 -2021-06-11
CVE-2020-13667 Drupal 安全漏洞 7.5 -2021-05-17
CVE-2020-13664 Drupal 命令注入漏洞 8.8 -2021-05-05

All 55 known CVE vulnerabilities affecting drupal core with full Chinese analysis, references, and POCs where available.