Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Drupal core — Vulnerabilities & Security Advisories 50

All 50 CVE vulnerabilities found in Drupal core, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common vulnerability classifications, specifically Weakness Type 79 (Cross-site Scripting), for the vendor Drupal and their product Drupal core. The content collects historical security data covering a wide range of vulnerability severities and discovery dates, ensuring that users have access to a complete timeline of reported issues. By examining this aggregation, researchers and security professionals can effectively track a vendor's advisories over time, which helps in understanding the release cycle and patch management strategies employed by Drupal. Furthermore, users can gain a deeper understanding of a specific weakness class within the context of content management systems, seeing how abstract vulnerability models manifest in real-world software. The page also allows for a detailed look at a product's vulnerability history, highlighting trends in code quality and architectural security decisions. This structured approach facilitates better risk assessment and informs mitigation efforts without requiring manual compilation of data from multiple sources. It serves as a central reference point for analyzing how Drupal core has handled security flaws across different versions. Ultimately, this resource supports proactive security management by providing clear, organized insights into past incidents and their resolutions.

Vendor: drupal core

CVE IDTitleCVSSSeverityPublished
CVE-2026-9082 Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 CWE-89 9.8 Critical2026-05-20
CVE-2026-6367 Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003 CWE-79--2026-05-19
CVE-2026-6366 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 CWE-915--2026-05-19
CVE-2026-6365 Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 CWE-79--2026-05-19
CVE-2025-13083 Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 CWE-525 7.5AIHighAI2025-11-18
CVE-2025-13082 Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 CWE-451 4.3AIMediumAI2025-11-18
CVE-2025-13081 Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 CWE-915 9.8AICriticalAI2025-11-18
CVE-2025-13080 Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 CWE-754--AI2025-11-18
CVE-2025-31675 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 CWE-79 6.1 -2025-03-31
CVE-2025-31674 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 CWE-915 9.8 -2025-03-31
CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 CWE-863 6.5 -2025-03-31
CVE-2025-3057 Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 CWE-79 6.1 -2025-03-31
CVE-2024-55638 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008 CWE-915 9.8 -2024-12-09
CVE-2024-55637 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007 CWE-915 9.8 -2024-12-09
CVE-2024-55636 Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 CWE-915 9.8 -2024-12-09
CVE-2024-55635 Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005 CWE-79 6.1 -2024-12-09
CVE-2024-55634 Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004 CWE-178 8.8 -2024-12-09
CVE-2024-12393 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003 CWE-79 6.1 -2024-12-09
CVE-2024-11942 Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002 CWE-390 9.1 -2024-12-05
CVE-2024-11941 Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001 CWE-835 7.5 -2024-12-05
CVE-2024-45440 Drupal 安全漏洞 5.3AIMediumAI2024-08-29
CVE-2020-13688 Drupal Core 跨站脚本漏洞 6.1 -2021-06-11
CVE-2020-13663 Drupal 跨站请求伪造漏洞 8.8 -2021-06-11
CVE-2020-13667 Drupal 安全漏洞 7.5 -2021-05-17
CVE-2020-13664 Drupal 命令注入漏洞 8.8 -2021-05-05
CVE-2020-13662 IBM API Connect 输入验证错误漏洞 6.1 -2021-05-05
CVE-2020-13665 Drupal 安全漏洞 9.8 -2021-05-05
CVE-2020-13666 Drupal 跨站脚本漏洞 6.1 -2021-05-05
CVE-2020-13671 Drupal core 代码问题漏洞 8.8 -2020-11-20
CVE-2019-6342 Drupal core - Critical - Access bypass - SA-CORE-2019-008 7.5 -2020-05-28

All 50 known CVE vulnerabilities affecting Drupal core with full Chinese analysis, references, and POCs where available.