Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Drupal — Vulnerabilities & Security Advisories 309

Browse all 309 CVE security advisories affecting Drupal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Drupal is an open-source content management framework primarily utilized for building complex websites and digital experiences. With 295 recorded CVEs, its security history reflects typical challenges faced by widely adopted PHP-based platforms. Common vulnerability classes include remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or insecure configuration defaults. Notable incidents have frequently involved exposed administrative endpoints or flawed permission handling, allowing attackers to gain unauthorized access or inject malicious scripts. The platform’s modular architecture, while flexible, can introduce risk if contributed modules are not rigorously vetted or updated. Security posture largely depends on timely patching and strict adherence to hardening guidelines. Despite these historical issues, Drupal remains a robust tool for enterprise-level applications, provided administrators maintain vigilant oversight of installed extensions and system configurations to mitigate known attack vectors effectively.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13282 Block permissions - Moderately critical - Access bypass - SA-CONTRIB-2024-046 — Block permissionsCWE-863 5.3 -2025-01-09
CVE-2024-13281 Monster Menus - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-045 — Monster MenusCWE-863 7.5 -2025-01-09
CVE-2024-13280 Persistent Login - Moderately critical - Access bypass - SA-CONTRIB-2024-044 — Persistent LoginCWE-613 9.1 -2025-01-09
CVE-2024-13279 Two-factor Authentication (TFA) - Critical - Access bypass - SA-CONTRIB-2024-043 — Two-factor Authentication (TFA)CWE-384 7.1 -2025-01-09
CVE-2024-13278 Diff - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-042 — DiffCWE-863 8.8 -2025-01-09
CVE-2024-13277 Smart IP Ban - Critical - Access bypass - SA-CONTRIB-2024-041 — Smart IP BanCWE-863 9.1 -2025-01-09
CVE-2024-13276 File Entity (fieldable files) - Moderately critical - Information Disclosure - SA-CONTRIB-2024-040 — File Entity (fieldable files)CWE-201 7.1 -2025-01-09
CVE-2024-13275 Security Kit - Less critical - Denial of Service - SA-CONTRIB-2024-039 — Security KitCWE-843 7.5 -2025-01-09
CVE-2024-13274 Open Social - Moderately critical - Denial of Service - SA-CONTRIB-2024-038 — Open SocialCWE-799 9.8 -2025-01-09
CVE-2024-13273 Open Social - Moderately critical - Cross Site Scripting, Denial of Service - SA-CONTRIB-2024-037 — Open SocialCWE-79 6.1 -2025-01-09
CVE-2024-13272 Paragraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-036 — Paragraphs tableCWE-1220 4.3 -2025-01-09
CVE-2024-13271 Content Entity Clone - Moderately critical - Information Disclosure - SA-CONTRIB-2024-035 — Content Entity CloneCWE-863 9.1 -2025-01-09
CVE-2024-13270 Freelinking - Moderately critical - Information Disclosure - SA-CONTRIB-2024-034 — FreelinkingCWE-863 7.5 -2025-01-09
CVE-2024-13269 Advanced Varnish - Moderately critical - Access bypass - SA-CONTRIB-2024-033 — Advanced VarnishCWE-201 9.1 -2025-01-09
CVE-2024-13268 Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032 — OpignoCWE-96 9.8 -2025-01-09
CVE-2024-13267 Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031 — Opigno TinCan Question TypeCWE-96 9.8 -2025-01-09
CVE-2024-13266 Responsive and off-canvas menu - Moderately critical - Access bypass - SA-CONTRIB-2024-030 — Responsive and off-canvas menuCWE-863 7.5 -2025-01-09
CVE-2024-13265 Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029 — Opigno Learning pathCWE-96 8.8 -2025-01-09
CVE-2024-13264 Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028 — Opigno moduleCWE-96 9.8 -2025-01-09
CVE-2024-13263 Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027 — Opigno group managerCWE-96 8.8 -2025-01-09
CVE-2024-13262 View Password - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-026 — View PasswordCWE-79 6.1 -2025-01-09
CVE-2024-13261 Acquia DAM - Moderately critical - Cross Site Request Forgery, Denial of Service - SA-CONTRIB-2024-025 — Acquia DAMCWE-352 8.8 -2025-01-09
CVE-2024-13260 Migrate queue importer - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-024 — Migrate queue importerCWE-352 8.8 -2025-01-09
CVE-2024-13259 Image Sizes - Moderately critical - Access bypass - SA-CONTRIB-2024-023 — Image SizesCWE-201 9.1 -2025-01-09
CVE-2024-13258 Drupal REST & JSON API Authentication - Moderately critical - Access bypass - SA-CONTRIB-2024-022 — Drupal REST & JSON API AuthenticationCWE-863 8.2 -2025-01-09
CVE-2024-13257 Commerce View Receipt - Moderately critical - Access bypass - SA-CONTRIB-2024-021 — Commerce View ReceiptCWE-863 7.5 -2025-01-09
CVE-2024-13256 Email Contact - Moderately critical - Access bypass - SA-CONTRIB-2024-020 — Email ContactCWE-1220 7.5 -2025-01-09
CVE-2024-13255 RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019 — RESTful Web ServicesCWE-202 5.3 -2025-01-09
CVE-2024-13254 REST Views - Moderately critical - Information Disclosure - SA-CONTRIB-2024-018 — REST ViewsCWE-201 5.3 -2025-01-09
CVE-2024-13253 Advanced PWA - Critical - Access bypass - SA-CONTRIB-2024-017 — Advanced PWA inc Push NotificationsCWE-863 8.2 -2025-01-09

This page lists every published CVE security advisory associated with Drupal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.