Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

drupal core — Vulnerabilities & Security Advisories 46

All 46 CVE vulnerabilities found in drupal core, with AI-generated Chinese analysis, references, and POCs.

This page details known security vulnerabilities associated with the Drupal core software, focusing on common weakness categories such as code injection, cross-site scripting, and broken access control. It serves as a centralized repository for understanding the historical security posture of this widely used content management system framework. The content here aggregates vulnerability data spanning from the early release cycles of Drupal 7 through to the most recent Drupal 10 releases. This comprehensive timeline allows users to analyze how security practices have evolved within the core codebase over more than a decade of active development and maintenance. By consolidating reports from the Drupal Security Team and external researchers, the page provides a holistic view of the threats that have impacted the platform. Visitors can utilize this resource to track vendor advisories issued by the Drupal Security Team, helping them stay informed about critical patches and recommended upgrade paths. Additionally, the page enables users to understand specific weakness classes in the context of PHP-based web applications, offering insights into how common flaws are exploited within the Drupal architecture. Users can also look up a product’s vulnerability history to assess risk exposure, compare severity levels across different versions, and identify patterns in recurring security issues. This structured approach supports both developers and security professionals in making informed decisions regarding system hardening, patch management, and long-term stability. The information is presented objectively to facilitate accurate risk assessment without unnecessary commentary.

Vendor: drupal core

CVE IDTitleCVSSSeverityPublished
CVE-2025-13083 Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 CWE-525 7.5AIHighAI2025-11-18
CVE-2025-13082 Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 CWE-451 4.3AIMediumAI2025-11-18
CVE-2025-13081 Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 CWE-915 9.8AICriticalAI2025-11-18
CVE-2025-13080 Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 CWE-754--AI2025-11-18
CVE-2025-31675 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 CWE-79 6.1 -2025-03-31
CVE-2025-31674 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 CWE-915 9.8 -2025-03-31
CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 CWE-863 6.5 -2025-03-31
CVE-2025-3057 Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 CWE-79 6.1 -2025-03-31
CVE-2024-55638 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008 CWE-915 9.8 -2024-12-09
CVE-2024-55637 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007 CWE-915 9.8 -2024-12-09
CVE-2024-55636 Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 CWE-915 9.8 -2024-12-09
CVE-2024-55635 Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005 CWE-79 6.1 -2024-12-09
CVE-2024-55634 Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004 CWE-178 8.8 -2024-12-09
CVE-2024-12393 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003 CWE-79 6.1 -2024-12-09
CVE-2024-11942 Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002 CWE-390 9.1 -2024-12-05
CVE-2024-11941 Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001 CWE-835 7.5 -2024-12-05
CVE-2024-45440 Drupal 安全漏洞 5.3AIMediumAI2024-08-29
CVE-2020-13688 Drupal Core 跨站脚本漏洞 6.1 -2021-06-11
CVE-2020-13663 Drupal 跨站请求伪造漏洞 8.8 -2021-06-11
CVE-2020-13667 Drupal 安全漏洞 7.5 -2021-05-17
CVE-2020-13664 Drupal 命令注入漏洞 8.8 -2021-05-05
CVE-2020-13662 IBM API Connect 输入验证错误漏洞 6.1 -2021-05-05
CVE-2020-13665 Drupal 安全漏洞 9.8 -2021-05-05
CVE-2020-13666 Drupal 跨站脚本漏洞 6.1 -2021-05-05
CVE-2020-13671 Drupal core 代码问题漏洞 8.8 -2020-11-20
CVE-2019-6342 Drupal core - Critical - Access bypass - SA-CORE-2019-008 7.5 -2020-05-28
CVE-2011-2726 Drupal 安全漏洞 7.5 -2019-11-15
CVE-2019-6341 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004 5.4 -2019-03-26
CVE-2019-6340 Drupal core - Highly critical - Remote Code Execution 8.1 -2019-02-21
CVE-2017-6923 Access bypass in Drupal 8 views 6.5 -2019-01-22

All 46 known CVE vulnerabilities affecting drupal core with full Chinese analysis, references, and POCs where available.