Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Drupal — Vulnerabilities & Security Advisories 309

Browse all 309 CVE security advisories affecting Drupal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Drupal is an open-source content management framework primarily utilized for building complex websites and digital experiences. With 295 recorded CVEs, its security history reflects typical challenges faced by widely adopted PHP-based platforms. Common vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure configuration defaults. Notable incidents have frequently involved exposed administrative endpoints or flawed permission handling, allowing attackers to gain unauthorized access or inject malicious scripts. The platform’s modular architecture, while flexible, can introduce risk if contributed modules are not rigorously vetted or updated. Security posture largely depends on timely patching and strict adherence to hardening guidelines. Despite these historical issues, Drupal remains a robust tool for enterprise-level applications, provided administrators maintain vigilant oversight of installed extensions and system configurations to mitigate known attack vectors effectively.

CVE IDTitleCVSSSeverityPublished
CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 — Drupal coreCWE-863 6.5 -2025-03-31
CVE-2025-3057 Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 — Drupal coreCWE-79 6.1 -2025-03-31
CVE-2024-13312 Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076 — Open SocialCWE-862 7.5 -2025-01-09
CVE-2024-13311 Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075 — Allow All File Extensions for file fields 8.2 -2025-01-09
CVE-2024-13310 Git Utilities for Drupal - Critical - Unsupported - SA-CONTRIB-2024-074 — Git Utilities for Drupal 9.1 -2025-01-09
CVE-2024-13309 Login Disable - Critical - Access bypass - SA-CONTRIB-2024-073 — Login DisableCWE-287 8.2 -2025-01-09
CVE-2024-13308 Browser Back Button - Moderately critical - Cross site scripting - SA-CONTRIB-2024-072 — Browser Back ButtonCWE-79 6.1 -2025-01-09
CVE-2024-13305 Entity Form Steps - Moderately critical - Cross site scripting - SA-CONTRIB-2024-071 — Entity Form StepsCWE-79 6.1 -2025-01-09
CVE-2024-13304 Minify JS - Moderately critical - Cross site request forgery - SA-CONTRIB-2024-070 — Minify JSCWE-352 8.8 -2025-01-09
CVE-2024-13303 Download All Files - Critical - Access bypass - SA-CONTRIB-2024-069 — Download All FilesCWE-862 7.5 -2025-01-09
CVE-2024-13302 Pages Restriction Access - Critical - Access bypass - SA-CONTRIB-2024-068 — Pages Restriction AccessCWE-863 7.5 -2025-01-09
CVE-2024-13301 OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) - Critical - Cross Site Scripting - SA-CONTRIB-2024-067 — OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client)CWE-79 6.1 -2025-01-09
CVE-2024-13300 Print Anything - Critical - Unsupported - SA-CONTRIB-2024-066 — Print Anything 8.2 -2025-01-09
CVE-2024-13299 Megamenu Framework - Critical - Unsupported - SA-CONTRIB-2024-065 — Megamenu Framework 9.4 -2025-01-09
CVE-2024-13298 Tarte au Citron - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-064 — Tarte au CitronCWE-79 6.1 -2025-01-09
CVE-2024-13297 Eloqua - Moderately critical - Arbitrary PHP code execution - SA-CONTRIB-2024-063 — EloquaCWE-502 9.8 -2025-01-09
CVE-2024-13296 Mailjet - Moderately critical - Arbitrary PHP code execution - SA-CONTRIB-2024-062 — MailjetCWE-502 9.8 -2025-01-09
CVE-2024-13295 Node export - Moderately critical - Arbitrary PHP code execution - SA-CONTRIB-2024-061 — Node exportCWE-502 9.8 -2025-01-09
CVE-2024-13294 POST File - Critical - Cross Site Scripting, Arbitrary PHP code execution - SA-CONTRIB-2024-060 — POST FileCWE-79 6.1 -2025-01-09
CVE-2024-13293 POST File - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-059 — POST FileCWE-352 8.8 -2025-01-09
CVE-2024-13292 Tooltip - Moderately critical - Cross site scripting - SA-CONTRIB-2024-058 — TooltipCWE-79 6.1 -2025-01-09
CVE-2024-13291 Basic HTTP Authentication - Critical - Access bypass - SA-CONTRIB-2024-057 — Basic HTTP AuthenticationCWE-863--2025-01-09
CVE-2024-13290 OhDear Integration - Moderately critical - Access bypass - SA-CONTRIB-2024-056 — OhDear IntegrationCWE-863 7.5 -2025-01-09
CVE-2024-13289 Cookiebot + GTM - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-055 — Cookiebot + GTMCWE-79 6.1 -2025-01-09
CVE-2024-13288 Monster Menus - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-052 — Monster MenusCWE-502 9.8 -2025-01-09
CVE-2024-13287 Views SVG Animation - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-051 — Views SVG AnimationCWE-79 6.1 -2025-01-09
CVE-2024-13286 SVG Embed - Moderately critical - Cross site scripting - SA-CONTRIB-2024-050 — SVG EmbedCWE-79 6.1 -2025-01-09
CVE-2024-13285 wkhtmltopdf - Highly critical - Unsupported - SA-CONTRIB-2024-049 — wkhtmltopdf 9.8 -2025-01-09
CVE-2024-13284 Gutenberg - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-048 — GutenbergCWE-352 8.8 -2025-01-09
CVE-2024-13283 Facets - Critical - Cross Site Scripting - SA-CONTRIB-2024-047 — FacetsCWE-79 6.1 -2025-01-09

This page lists every published CVE security advisory associated with Drupal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.