Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 249 CRITICAL 12 HIGH 57 MEDIUM 158 LOW 22
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • GPL v2
  • GPL v3
  • オープンソース

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
101 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 1 0
102 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 19 0
103 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 35 0
104 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 64 7
105 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 57 13
106 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 39 7
107 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 33 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
101 8.1
5.1
HIGH
Network
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY envi… CWE-601
Open Redirect
CVE-2016-5385 cpe:2.3:a:drupal:drupal:*:* 8.0.0 8.1.7 2024-11-21 11:54
2016-07-19
Show GitHub Exploit DB Packet Storm
102 8.1
6.8
HIGH
Network
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data trunc… CWE-19
 Data Processing Errors
CVE-2016-3171 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
103 5.3
5.0
MEDIUM
Network
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configur… CWE-200
Information Exposure
CVE-2016-3170 cpe:2.3:a:drupal:drupal:8.0:rc4
cpe:2.3:a:drupal:drupal:8.0:rc3
cpe:2.3:a:drupal:drupal:8.0:rc2
cpe:2.3:a:drup…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
104 8.1
6.8
HIGH
Network
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit ca… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3169 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
105 6.4
8.5
MEDIUM
Network
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrar… CWE-254
 7PK - Security Features
CVE-2016-3168 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
106 7.4
6.4
HIGH
Network
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishi… NVD-CWE-Other
CVE-2016-3167 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
107 5.9
4.3
MEDIUM
Network
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP re… NVD-CWE-Other
CVE-2016-3166 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
108 7.5
5.0
HIGH
Network
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a fo… CWE-284
Improper Access Control
CVE-2016-3165 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
109 7.4
5.8
HIGH
Network
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, rela… NVD-CWE-Other
CVE-2016-3164 cpe:2.3:a:drupal:drupal:8.0.3:*
cpe:2.3:a:drupal:drupal:8.0.2:*
cpe:2.3:a:drupal:drupal:8.0.1:*
cpe:2.3:a:drup…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm
110 7.5
5.0
HIGH
Network
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method. CWE-254
 7PK - Security Features
CVE-2016-3163 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:49
2016-04-13
Show GitHub Exploit DB Packet Storm