Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

drupal core — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in drupal core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for drupal core, a widely used open-source content management system framework. It compiles known weaknesses affecting the core software, focusing on common weakness classifications such as cross-site scripting, remote code execution, and privilege escalation. The database covers historical records from 2014 to the present, ensuring comprehensive coverage of security incidents that have impacted this specific product line. By organizing these entries systematically, the resource allows users to track vendor advisories and understand the evolution of security flaws within the Drupal ecosystem. Readers can utilize this collection to look up a product's vulnerability history, examining trends in attack vectors and the frequency of disclosures over time. This structured approach helps developers and security analysts identify patterns in how specific weakness classes have been exploited or remediated in past releases. The information serves as a factual reference for assessing risk profiles and prioritizing patching efforts based on historical severity and impact. Rather than offering subjective recommendations, the page provides objective data points that facilitate informed decision-making during security audits or compliance reviews. Users interested in the broader context of web application security can also explore how Drupal core vulnerabilities relate to industry-wide standards and mitigation strategies. This aggregation aims to reduce the time required to research individual security incidents by centralizing relevant information in one accessible location. The content is regularly updated to reflect new disclosures and revised assessments from trusted security sources.

Vendor: drupal core

CVE IDTitleCVSSSeverityPublished
CVE-2026-55808 Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009 CWE-79--2026-07-10
CVE-2026-55807 Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008 CWE-918--2026-07-10
CVE-2026-55806 Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007 CWE-601--2026-07-10
CVE-2026-55804 Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006 CWE-915--2026-07-10
CVE-2026-55803 Drupal core - Critical - PHP object injection - SA-CORE-2026-005 CWE-915--2026-07-10
CVE-2026-9082 Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 CWE-89 9.8 Critical2026-05-20
CVE-2026-6367 Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003 CWE-79--2026-05-19
CVE-2026-6366 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 CWE-915--2026-05-19
CVE-2026-6365 Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 CWE-79--2026-05-19
CVE-2025-13083 Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 CWE-525 7.5AIHighAI2025-11-18
CVE-2025-13082 Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 CWE-451 4.3AIMediumAI2025-11-18
CVE-2025-13081 Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 CWE-915 9.8AICriticalAI2025-11-18
CVE-2025-13080 Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 CWE-754--AI2025-11-18
CVE-2025-31675 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 CWE-79 6.1 -2025-03-31
CVE-2025-31674 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 CWE-915 9.8 -2025-03-31
CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 CWE-863 6.5 -2025-03-31
CVE-2025-3057 Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 CWE-79 6.1 -2025-03-31
CVE-2024-55638 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008 CWE-915 9.8 -2024-12-09
CVE-2024-55637 Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007 CWE-915 9.8 -2024-12-09
CVE-2024-55636 Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 CWE-915 9.8 -2024-12-09
CVE-2024-55635 Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005 CWE-79 6.1 -2024-12-09
CVE-2024-55634 Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004 CWE-178 8.8 -2024-12-09
CVE-2024-12393 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003 CWE-79 6.1 -2024-12-09
CVE-2024-11942 Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002 CWE-390 9.1 -2024-12-05
CVE-2024-11941 Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001 CWE-835 7.5 -2024-12-05
CVE-2024-45440 Drupal 安全漏洞 5.3AIMediumAI2024-08-29
CVE-2020-13688 Drupal Core 跨站脚本漏洞 6.1 -2021-06-11
CVE-2020-13663 Drupal 跨站请求伪造漏洞 8.8 -2021-06-11
CVE-2020-13667 Drupal 安全漏洞 7.5 -2021-05-17
CVE-2020-13664 Drupal 命令注入漏洞 8.8 -2021-05-05

All 55 known CVE vulnerabilities affecting drupal core with full Chinese analysis, references, and POCs where available.