Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 254 CRITICAL 12 HIGH 57 MEDIUM 162 LOW 23
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • オープンソース
  • GPL v2
  • GPL v3

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
161 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 5 1
162 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 23 1
163 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 39 1
164 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 68 8
165 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 61 14
166 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 43 8
167 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 37 7
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
161 -
4.0
MEDIUM The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-1590 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 10:37
2012-10-1
Show GitHub Exploit DB Packet Storm
162 -
3.5
LOW Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain r… CWE-399
 Resource Management Errors
CVE-2012-1588 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 10:37
2012-10-1
Show GitHub Exploit DB Packet Storm
163 -
7.5
HIGH SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2012-2306 cpe:2.3:a:drupal:drupal:-:* 2024-11-21 10:38
2012-07-26
Show GitHub Exploit DB Packet Storm
164 -
5.0
MEDIUM The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installati… CWE-200
Information Exposure
CVE-2012-2922 cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal:drupal:7.7:*
cpe:2.3:a:drupal:dru…
7.14 2024-11-21 10:39
2012-05-22
Show GitHub Exploit DB Packet Storm
165 -
5.8
MEDIUM Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destina… CWE-20
 Improper Input Validation 
CVE-2012-1589 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
2024-11-21 10:37
2012-05-19
Show GitHub Exploit DB Packet Storm
166 -
6.8
MEDIUM Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout … CWE-352
 Origin Validation Error
CVE-2007-6752 cpe:2.3:a:drupal:drupal:7.x-dev:*
cpe:2.3:a:drupal:drupal:7.9:*
cpe:2.3:a:drupal:drupal:7.8:*
cpe:2.3:a:drupal…
7.12 2024-11-21 09:40
2012-03-28
Show GitHub Exploit DB Packet Storm
167 -
5.0
MEDIUM Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/… CWE-200
Information Exposure
CVE-2011-3730 cpe:2.3:a:drupal:drupal:7.0:* 2024-11-21 10:31
2011-09-24
Show GitHub Exploit DB Packet Storm
168 -
7.5
HIGH Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table. CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-2687 cpe:2.3:a:drupal:drupal:7.2:*
cpe:2.3:a:drupal:drupal:7.1:*
cpe:2.3:a:drupal:drupal:7.0:rc4
cpe:2.3:a:drupal:d…
2024-11-21 10:28
2011-07-27
Show GitHub Exploit DB Packet Storm
169 -
5.0
MEDIUM The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attacker… CWE-287
Improper Authentication
CVE-2010-3686 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 10:19
2010-09-30
Show GitHub Exploit DB Packet Storm
170 -
5.0
MEDIUM The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which all… CWE-287
Improper Authentication
CVE-2010-3685 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2024-11-21 10:19
2010-09-30
Show GitHub Exploit DB Packet Storm