Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 254 CRITICAL 12 HIGH 57 MEDIUM 162 LOW 23
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • GPL v3
  • オープンソース
  • GPL v2

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
181 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 5 1
182 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 23 1
183 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 39 1
184 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 68 8
185 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 61 14
186 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 43 8
187 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 37 7
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
181 -
6.5
MEDIUM Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote auth… CWE-94
Code Injection
CVE-2009-2372 cpe:2.3:a:drupal:drupal:*:* 6.0 6.13 2026-04-23 09:35
2009-07-9
Show GitHub Exploit DB Packet Storm
182 -
3.5
LOW Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte se… CWE-79
Cross-site Scripting
CVE-2009-1844 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-06-1
Show GitHub Exploit DB Packet Storm
183 -
4.3
MEDIUM Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims i… NVD-CWE-noinfo
CVE-2009-1576 cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:drupal:6.8:*
cpe:2.3:a:drupal:drupal:6.7:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-05-7
Show GitHub Exploit DB Packet Storm
184 -
4.3
MEDIUM Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted U… CWE-79
Cross-site Scripting
CVE-2009-1575 cpe:2.3:a:drupal:drupal:6:beta1
cpe:2.3:a:drupal:drupal:6:*
cpe:2.3:a:drupal:drupal:6.9:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-05-7
Show GitHub Exploit DB Packet Storm
185 -
4.3
MEDIUM Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to c… CWE-79
Cross-site Scripting
CVE-2008-6533 cpe:2.3:a:drupal:drupal:6.6:*
cpe:2.3:a:drupal:drupal:6.5:*
cpe:2.3:a:drupal:drupal:6.4:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-03-27
Show GitHub Exploit DB Packet Storm
186 -
6.8
MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser v… CWE-352
 Origin Validation Error
CVE-2008-6532 cpe:2.3:a:drupal:drupal:6.6:*
cpe:2.3:a:drupal:drupal:6.5:*
cpe:2.3:a:drupal:drupal:6.4:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-03-27
Show GitHub Exploit DB Packet Storm
187 -
9.3
HIGH includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the… CWE-16
CWE-20
Configuration
 Improper Input Validation 
CVE-2008-6171 cpe:2.3:a:drupal:drupal:6.5:*
cpe:2.3:a:drupal:drupal:6.4:*
cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-02-20
Show GitHub Exploit DB Packet Storm
188 -
3.5
LOW Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbi… CWE-79
Cross-site Scripting
CVE-2008-6170 cpe:2.3:a:drupal:drupal:6.5:*
cpe:2.3:a:drupal:drupal:6.4:*
cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2009-02-20
Show GitHub Exploit DB Packet Storm
189 -
7.5
HIGH The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors related to contributed modules. CWE-264
NVD-CWE-noinfo
Permissions, Privileges, and Access Controls
CVE-2008-4793 cpe:2.3:a:drupal:drupal:5.9:*
cpe:2.3:a:drupal:drupal:5.8:*
cpe:2.3:a:drupal:drupal:5.7:*
cpe:2.3:a:drupal:dru…
5.10 2026-04-23 09:35
2008-10-30
Show GitHub Exploit DB Packet Storm
190 -
6.0
MEDIUM The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypas… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-4792 cpe:2.3:a:drupal:drupal:*:* 5.0
6.0


5.11
6.5
2026-04-23 09:35
2008-10-30
Show GitHub Exploit DB Packet Storm