Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 254 CRITICAL 12 HIGH 57 MEDIUM 162 LOW 23
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • GPL v2
  • GPL v3
  • オープンソース

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
101 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 5 1
102 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 23 1
103 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 39 1
104 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 68 8
105 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 61 14
106 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 43 8
107 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 37 7
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
101 4.3
4.0
MEDIUM
Network
The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions an… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-7572 cpe:2.3:a:drupal:drupal:8.1.9:*
cpe:2.3:a:drupal:drupal:8.1.8:*
cpe:2.3:a:drupal:drupal:8.1.7:*
cpe:2.3:a:drup…
2024-11-21 11:58
2016-10-4
Show GitHub Exploit DB Packet Storm
102 6.1
4.3
MEDIUM
Network
Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception. CWE-79
Cross-site Scripting
CVE-2016-7571 cpe:2.3:a:drupal:drupal:8.1.9:*
cpe:2.3:a:drupal:drupal:8.1.8:*
cpe:2.3:a:drupal:drupal:8.1.7:*
cpe:2.3:a:drup…
2024-11-21 11:58
2016-10-4
Show GitHub Exploit DB Packet Storm
103 4.3
4.0
MEDIUM
Network
Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging righ… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-7570 cpe:2.3:a:drupal:drupal:8.1.9:*
cpe:2.3:a:drupal:drupal:8.1.8:*
cpe:2.3:a:drupal:drupal:8.1.7:*
cpe:2.3:a:drup…
2024-11-21 11:58
2016-10-4
Show GitHub Exploit DB Packet Storm
104 5.3
5.0
MEDIUM
Network
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensiti… CWE-200
Information Exposure
CVE-2016-6212 cpe:2.3:a:drupal:drupal:8.1.2:*
cpe:2.3:a:drupal:drupal:8.1.1:*
cpe:2.3:a:drupal:drupal:8.1.0:rc1
cpe:2.3:a:dr…
2024-11-21 11:55
2016-09-9
Show GitHub Exploit DB Packet Storm
105 8.8
6.5
HIGH
Network
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-6211 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:55
2016-09-9
Show GitHub Exploit DB Packet Storm
106 8.1
5.1
HIGH
Network
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY envi… CWE-601
Open Redirect
CVE-2016-5385 cpe:2.3:a:drupal:drupal:*:* 8.0.0 8.1.7 2024-11-21 11:54
2016-07-19
Show GitHub Exploit DB Packet Storm
107 8.1
6.8
HIGH
Network
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data trunc… CWE-19
 Data Processing Errors
CVE-2016-3171 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
108 5.3
5.0
MEDIUM
Network
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configur… CWE-200
Information Exposure
CVE-2016-3170 cpe:2.3:a:drupal:drupal:8.0:rc4
cpe:2.3:a:drupal:drupal:8.0:rc3
cpe:2.3:a:drupal:drupal:8.0:rc2
cpe:2.3:a:drup…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
109 8.1
6.8
HIGH
Network
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit ca… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3169 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
110 6.4
8.5
MEDIUM
Network
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrar… CWE-254
 7PK - Security Features
CVE-2016-3168 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm