Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 254 CRITICAL 12 HIGH 57 MEDIUM 162 LOW 23
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • オープンソース
  • GPL v2
  • GPL v3

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
131 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 5 1
132 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 23 1
133 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 39 1
134 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 68 8
135 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 61 14
136 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 43 8
137 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 37 7
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
131 -
6.8
MEDIUM modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-5267 cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal:drupal:7.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 11:11
2014-09-30
Show GitHub Exploit DB Packet Storm
132 -
5.0
MEDIUM The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote atta… CWE-399
 Resource Management Errors
CVE-2014-5266 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:11
2014-08-18
Show GitHub Exploit DB Packet Storm
133 -
5.0
MEDIUM The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion,… CWE-399
 Resource Management Errors
CVE-2014-5265 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:11
2014-08-18
Show GitHub Exploit DB Packet Storm
134 -
4.3
MEDIUM Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled t… CWE-79
Cross-site Scripting
CVE-2014-5022 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:11
2014-07-22
Show GitHub Exploit DB Packet Storm
135 -
2.1
LOW Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject a… CWE-79
Cross-site Scripting
CVE-2014-5021 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:11
2014-07-22
Show GitHub Exploit DB Packet Storm
136 -
4.9
MEDIUM The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-5020 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:11
2014-07-22
Show GitHub Exploit DB Packet Storm
137 -
5.0
MEDIUM The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration fil… CWE-20
 Improper Input Validation 
CVE-2014-5019 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 11:11
2014-07-22
Show GitHub Exploit DB Packet Storm
138 -
5.0
MEDIUM Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input informati… CWE-200
Information Exposure
CVE-2014-2983 cpe:2.3:a:drupal:drupal:*:* 7.0
6.0


7.27
6.31
2024-11-21 11:07
2014-04-24
Show GitHub Exploit DB Packet Storm
139 -
4.3
MEDIUM Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: thi… CWE-79
Cross-site Scripting
CVE-2014-1607 cpe:2.3:a:drupal:drupal:7.14:* 2024-11-21 11:04
2014-01-27
Show GitHub Exploit DB Packet Storm
140 -
4.0
MEDIUM The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to ob… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1476 cpe:2.3:a:drupal:drupal:7.2:*
cpe:2.3:a:drupal:drupal:7.24:*
cpe:2.3:a:drupal:drupal:7.23:*
cpe:2.3:a:drupal:d…
2024-11-21 11:04
2014-01-25
Show GitHub Exploit DB Packet Storm