Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 254 CRITICAL 12 HIGH 57 MEDIUM 162 LOW 23
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • オープンソース
  • GPL v2
  • GPL v3

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
121 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 5 1
122 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 23 1
123 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 39 1
124 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 68 8
125 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 61 14
126 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 43 8
127 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 37 7
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
121 -
4.3
MEDIUM Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, rel… CWE-79
Cross-site Scripting
CVE-2015-6658 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:35
2015-08-24
Show GitHub Exploit DB Packet Storm
122 -
4.3
MEDIUM The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by t… CWE-20
 Improper Input Validation 
CVE-2015-3234 cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal:drupal:7.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:28
2015-06-23
Show GitHub Exploit DB Packet Storm
123 -
5.8
MEDIUM Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NVD-CWE-Other
CVE-2015-3233 cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal:drupal:7.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:28
2015-06-23
Show GitHub Exploit DB Packet Storm
124 -
5.8
MEDIUM Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination… NVD-CWE-Other
CVE-2015-3232 cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal:drupal:7.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:28
2015-06-23
Show GitHub Exploit DB Packet Storm
125 -
4.0
MEDIUM The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache. CWE-200
Information Exposure
CVE-2015-3231 cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal:drupal:7.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:28
2015-06-23
Show GitHub Exploit DB Packet Storm
126 -
3.5
LOW Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a craf… CWE-284
Improper Access Control
CVE-2015-2559 cpe:2.3:a:drupal:drupal:*:* 6.0
7.0


6.35
7.35
2024-11-21 11:27
2015-03-25
Show GitHub Exploit DB Packet Storm
127 6.1
4.3
MEDIUM
Network
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. CWE-79
Cross-site Scripting
CVE-2010-5312 cpe:2.3:a:drupal:drupal:*:* 7.0 7.86 2024-11-21 10:23
2014-11-25
Show GitHub Exploit DB Packet Storm
128 -
5.0
MEDIUM The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and m… NVD-CWE-noinfo
CVE-2014-9016 cpe:2.3:a:drupal:drupal:*:* 7.0 7.34 2024-11-21 11:20
2014-11-25
Show GitHub Exploit DB Packet Storm
129 -
6.8
MEDIUM Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS session… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-9015 cpe:2.3:a:drupal:drupal:*:* 6.0
7.0


6.34
7.34
2024-11-21 11:20
2014-11-25
Show GitHub Exploit DB Packet Storm
130 -
7.5
HIGH The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection att… CWE-89
SQL Injection
CVE-2014-3704 cpe:2.3:a:drupal:drupal:*:* 7.0 7.32 2024-11-21 11:08
2014-10-16
Show GitHub Exploit DB Packet Storm