| Drupal | Number Of NVD | 254 | CRITICAL | 12 | HIGH | 57 | MEDIUM | 162 | LOW | 23 |
| URL | https://www.drupal.org/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Drupal is an open source Content Management System (CMS). Compared to WordPress and Joomla, it is said to be faster in displaying pages. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://www.drupal.org/download | ||
| 2 | https://www.drupal.org/project/drupal/releases | ||
| 3 | https://github.com/drupal/drupal | ||
| 4 | https://www.drupal.org/about/drupal6-eol | ||
| 5 | https://www.drupal.org/blog/drupal-7-8-and-9 |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 91 | Drupal 10 | 10.6.0-beta1 | Nov. 25, 2025 | Dec. 15, 2022 | 1 | 1 | 5 | 1 | |||
| 92 | Drupal 9 | 9.5.11 | Sept. 20, 2023 | June 3, 2020 | 3 | 20 | 23 | 1 | |||
| 93 | Drupal 8 | 8.9.20 | Nov. 17, 2021 | June 3, 2020 | Nov. 30, 2021 | 11 | 29 | 39 | 1 | ||
| 94 | Drupal 7 | 7.103 | Dec. 4, 2024 | Jan. 5, 2011 | Nov. 30, 2021 | 4 | 18 | 68 | 8 | ||
| 95 | Drupal 6 | 6.38 | Feb. 24, 2016 | Feb. 13, 2008 | Feb. 24, 2016 | 2 | 10 | 61 | 14 | ||
| 96 | Drupal 5 | 5.23 | Aug. 11, 2010 | Jan. 15, 2007 | Jan. 6, 2011 | 1 | 5 | 43 | 8 | ||
| 97 | Drupal 4 | 4.7.11 | Jan. 10, 2008 | June 15, 2002 | Jan. 1, 1900 | 1 | 7 | 37 | 7 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 91 |
6.1 5.8 |
MEDIUM
Network |
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi… |
CWE-601
Open Redirect |
CVE-2015-2750 |
cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal:drupal:7.7:* cpe:2.3:a:drupal:dru… |
2024-11-21 11:27 2017-09-14 |
Show | GitHub Exploit DB Packet Storm | ||||
| 92 |
6.1 5.8 |
MEDIUM
Network |
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination pa… |
CWE-601
Open Redirect |
CVE-2015-2749 |
cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal:drupal:7.7:* cpe:2.3:a:drupal:dru… |
2024-11-21 11:27 2017-09-14 |
Show | GitHub Exploit DB Packet Storm | ||||
| 93 |
7.5 6.0 |
HIGH
Network |
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests. |
NVD-CWE-noinfo
|
CVE-2017-6919 |
cpe:2.3:a:drupal:drupal:8.3.0:rc2 cpe:2.3:a:drupal:drupal:8.3.0:rc1 cpe:2.3:a:drupal:drupal:8.3.0:beta1 cpe:2.… |
2024-11-21 12:30 2017-04-20 |
Show | GitHub Exploit DB Packet Storm | ||||
| 94 |
8.1 6.8 |
HIGH
Network |
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, a… |
CWE-829
Inclusion of Functionality from Untrusted Control Sphere |
CVE-2017-6381 |
cpe:2.3:a:drupal:drupal:8.2.1:* cpe:2.3:a:drupal:drupal:8.2.0:rc2 cpe:2.3:a:drupal:drupal:8.2.0:rc1 cpe:2.3:a:… |
2024-11-21 12:29 2017-03-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 95 |
7.5 5.1 |
HIGH
Network |
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that use… |
CWE-352
Origin Validation Error |
CVE-2017-6379 |
cpe:2.3:a:drupal:drupal:8.2.6:* cpe:2.3:a:drupal:drupal:8.2.5:* cpe:2.3:a:drupal:drupal:8.2.4:* cpe:2.3:a:drup… |
2024-11-21 12:29 2017-03-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 96 |
7.5 5.0 |
HIGH
Network |
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass. |
CWE-863
Incorrect Authorization |
CVE-2017-6377 |
cpe:2.3:a:drupal:drupal:8.2.6:* cpe:2.3:a:drupal:drupal:8.2.5:* cpe:2.3:a:drupal:drupal:8.2.4:* cpe:2.3:a:drup… |
2024-11-21 12:29 2017-03-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 97 |
6.5 4.3 |
MEDIUM
Network |
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL. |
CWE-20
Improper Input Validation |
CVE-2016-9452 |
cpe:2.3:a:drupal:drupal:8.2.2:* cpe:2.3:a:drupal:drupal:8.2.1:* cpe:2.3:a:drupal:drupal:8.2.0:rc2 cpe:2.3:a:dr… |
2024-11-21 12:01 2016-11-26 |
Show | GitHub Exploit DB Packet Storm | ||||
| 98 |
6.8 4.9 |
MEDIUM
Network |
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors. |
CWE-601
Open Redirect |
CVE-2016-9451 |
cpe:2.3:a:drupal:drupal:7.51:* cpe:2.3:a:drupal:drupal:7.50:* cpe:2.3:a:drupal:drupal:7.4:* cpe:2.3:a:drupal:d… |
2024-11-21 12:01 2016-11-26 |
Show | GitHub Exploit DB Packet Storm | ||||
| 99 |
7.5 5.0 |
HIGH
Network |
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context. |
CWE-345
Insufficient Verification of Data Authenticity |
CVE-2016-9450 |
cpe:2.3:a:drupal:drupal:8.2.2:* cpe:2.3:a:drupal:drupal:8.2.1:* cpe:2.3:a:drupal:drupal:8.2.0:rc2 cpe:2.3:a:dr… |
2024-11-21 12:01 2016-11-26 |
Show | GitHub Exploit DB Packet Storm | ||||
| 100 |
4.3 4.0 |
MEDIUM
Network |
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of acc… |
CWE-200
Information Exposure |
CVE-2016-9449 |
cpe:2.3:a:drupal:drupal:8.2.2:* cpe:2.3:a:drupal:drupal:8.2.1:* cpe:2.3:a:drupal:drupal:8.2.0:rc2 cpe:2.3:a:dr… |
2024-11-21 12:01 2016-11-26 |
Show | GitHub Exploit DB Packet Storm |