Drupal Core vulnerabilities
49 known vulnerabilities affecting drupal/drupal_core.
Total CVEs
49
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL7HIGH12MEDIUM28LOW2
Vulnerabilities
Page 3 of 3
CVE-2025-31675P4MEDIUMCVSS 5.4≥ 8.0.0, < 10.3.14≥ 10.4.0, < 10.4.5+2 more2025-03-31
CVE-2025-31675 [MEDIUM] CWE-79 CVE-2025-31675: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5. It also affects the Drupal 7 module from versions 7.x-1.
nvd
CVE-2025-31673P4MEDIUMCVSS 4.6≥ 8.0.0, < 10.3.13≥ 10.4.0, < 10.4.3+2 more2025-03-31
CVE-2025-31673 [MEDIUM] CWE-863 CVE-2025-31673: Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affe
Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.
nvd
CVE-2024-55635P4MEDIUMCVSS 6.1≥ 7.0, < 7.1022024-12-10
CVE-2024-55635 [MEDIUM] CWE-79 CVE-2024-55635: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.
nvd
CVE-2024-12393P4MEDIUMCVSS 5.4≥ 8.8.0, < 10.2.11≥ 10.3.0, < 10.3.9+1 more2024-12-10
CVE-2024-12393 [MEDIUM] CWE-79 CVE-2024-12393: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
nvd
CVE-2026-15917P4MEDIUMCVSS 4.7≥ 11.3.0, < 11.3.14≥ 11.4.0, < 11.4.4+1 more2026-08-25
CVE-2026-15917 [MEDIUM] CWE-79 CVE-2026-15917: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
nvd
CVE-2026-15916P4MEDIUMCVSS 4.2≥ 0.0.0, < 10.6.13≥ 11.3.0, < 11.3.14+4 more2026-08-25
CVE-2026-15916 [MEDIUM] CWE-862 CVE-2026-15916: Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affec
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
nvd
CVE-2025-13083P4LOWCVSS 3.7≥ 8.0.0, < 10.4.9≥ 10.5.0, < 10.5.6+3 more2025-11-18
CVE-2025-13083 [LOW] CWE-525 CVE-2025-13083: Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows
Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.
nvd
CVE-2026-55807P4LOWCVSS 3.1≥ 0.0.0, < 10.5.12≥ 10.6.0, < 10.6.11+4 more2026-07-10
CVE-2026-55807 [LOW] CWE-918 CVE-2026-55807: Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Fo
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
nvd
CVE-2025-13082MEDIUMCVSS 4.3≥ 8.0.0, < 10.4.9≥ 10.5.0, < 10.5.6+2 more2025-11-18
CVE-2025-13082 [MEDIUM] CWE-451 Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
cvelistv5
← Previous3 / 3