Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal MEDIUM 5.9
CVE-2026-55803

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issu…

Fix: 10.5.12 / 10.6.11+
Fix from $1,600 2026-07-10
Drupal MEDIUM 5.9
CVE-2026-55804

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issu…

Fix: 10.5.12 / 10.6.11+
Fix from $1,600 2026-07-10
Drupal MEDIUM 5.9
CVE-2026-55806

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versi…

Fix: 10.5.12 / 10.6.11+
Fix from $1,600 2026-07-10
Drupal MEDIUM 5.4
CVE-2026-55808

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 10.5.12 / 10.6.11+
Fix from $1,600 2026-07-10
Drupal CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This …

Fix: 10.4.10 / 10.5.10+
Fix from $2,300 2026-05-20
Drupal MEDIUM 6.6
CVE-2026-6366

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This iss…

Fix: 10.5.9 / 10.6.7+
Fix from $1,600 2026-05-19
Drupal MEDIUM 6.1
CVE-2026-6365

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 10.5.9 / 10.6.7+
Fix from $1,600 2026-05-19
Drupal MEDIUM 6.1
CVE-2026-6367

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 11.3.7+
Fix from $1,600 2026-05-19
Drupal MEDIUM 5.9
CVE-2025-13081

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue…

Fix: 10.4.9 / 10.5.6+
Fix from $1,600 2025-11-18
Drupal MEDIUM 5.3
CVE-2025-13080

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro…

Fix: 10.4.9 / 10.5.6+
Fix from $1,600 2025-11-18
Cookies Consent Management HIGH 8.6
CVE-2025-48914

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-…

Fix: 1.2.15+
Fix from $1,950 2025-06-13
Cookies Consent Management HIGH 8.6
CVE-2025-48915

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-…

Fix: 1.2.15+
Fix from $1,950 2025-06-13
Panels MEDIUM 6.5
CVE-2025-3474

Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.T…

Fix: 4.9+
Fix from $1,600 2025-04-09
Eca\ MEDIUM 5.4
CVE-2025-3131

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: E…

Fix: 1.1.12 / 2.0.16+
Fix from $1,600 2025-04-09
Obfuscate MEDIUM 5.4
CVE-2025-3130

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue a…

Fix: 2.0.1+
Fix from $1,600 2025-04-02
Drupal MEDIUM 6.1
CVE-2025-3057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 10.3.13 / 10.4.3+
Fix from $1,600 2025-03-31
Drupal MEDIUM 5.4
CVE-2025-31675

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting …

Fix: 10.3.14 / 10.4.5+
Fix from $1,600 2025-03-31
Drupal HIGH 7.5
CVE-2025-31674

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue…

Fix: 10.3.13 / 10.4.3+
Fix from $1,950 2025-03-31
Drupal CRITICAL 9.8
CVE-2024-55636

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro…

Fix: 10.2.11 / 10.3.9+
Fix from $2,300 2024-12-10
Drupal CRITICAL 9.8
CVE-2024-55637

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fro…

Fix: 10.2.11 / 10.3.9+
Fix from $2,300 2024-12-10
Drupal CRITICAL 9.8
CVE-2024-55638

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.…

Fix: 7.102 / 10.2.11+
Fix from $2,300 2024-12-10
Drupal HIGH 8.1
CVE-2024-55634

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from…

Fix: 10.2.11 / 10.3.9+
Fix from $1,950 2024-12-10
Drupal MEDIUM 6.1
CVE-2024-55635

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting …

Fix: 7.102+
Fix from $1,600 2024-12-10
Drupal MEDIUM 5.4
CVE-2024-12393

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting …

Fix: 10.2.11 / 10.3.9+
Fix from $1,600 2024-12-10
Drupal HIGH 7.5
CVE-2024-11941

A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

Fix: 10.1.8 / 10.2.2+
Fix from $1,950 2024-12-05
Drupal MEDIUM 5.9
CVE-2024-11942

A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.

Fix: 10.2.10+
Fix from $1,600 2024-12-05
Drupal MEDIUM 5.3
CVE-2024-45440EPSS 9%

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of…

No fix yet
Fix from $1,600 2024-08-29
Drupal HIGH 7.5
CVE-2024-22362

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a…

Mitigation only
Fix from $1,950 2024-01-16
Drupal HIGH 7.5
CVE-2023-5256

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cac…

Fix: 9.5.11 / 10.0.11+
Fix from $1,950 2023-09-28
Drupal MEDIUM 6.5
CVE-2023-31250

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files t…

Fix: 7.96 / 9.4.14+
Fix from $1,600 2023-04-26