Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Drupal Number Of NVD 254 CRITICAL 12 HIGH 57 MEDIUM 162 LOW 23
URL https://www.drupal.org/
Explanation Drupal is an open source Content Management System (CMS).
Compared to WordPress and Joomla, it is said to be faster in displaying pages.
Tag
  • GPL v2
  • GPL v3
  • オープンソース

Add Information URL
No Type Name URL
1 https://www.drupal.org/download
2 https://www.drupal.org/project/drupal/releases
3 https://github.com/drupal/drupal
4 https://www.drupal.org/about/drupal6-eol
5 https://www.drupal.org/blog/drupal-7-8-and-9

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
191 Drupal 10 10.6.0-beta1 Nov. 25, 2025 Dec. 15, 2022 1 1 5 1
192 Drupal 9 9.5.11 Sept. 20, 2023 June 3, 2020 3 20 23 1
193 Drupal 8 8.9.20 Nov. 17, 2021 June 3, 2020 Nov. 30, 2021 11 29 39 1
194 Drupal 7 7.103 Dec. 4, 2024 Jan. 5, 2011 Nov. 30, 2021 4 18 68 8
195 Drupal 6 6.38 Feb. 24, 2016 Feb. 13, 2008 Feb. 24, 2016 2 10 61 14
196 Drupal 5 5.23 Aug. 11, 2010 Jan. 15, 2007 Jan. 6, 2011 1 5 43 8
197 Drupal 4 4.7.11 Jan. 10, 2008 June 15, 2002 Jan. 1, 1900 1 7 37 7
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
191 -
6.0
MEDIUM The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-4791 cpe:2.3:a:drupal:drupal:*:* 5.0
6.0


5.11
6.5
2026-04-23 09:35
2008-10-30
Show GitHub Exploit DB Packet Storm
192 -
6.0
MEDIUM The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-4790 cpe:2.3:a:drupal:drupal:5.9:*
cpe:2.3:a:drupal:drupal:5.8:*
cpe:2.3:a:drupal:drupal:5.7:*
cpe:2.3:a:drupal:dru…
5.10 2026-04-23 09:35
2008-10-30
Show GitHub Exploit DB Packet Storm
193 -
6.0
MEDIUM The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "l… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-4789 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
6.4 2026-04-23 09:35
2008-10-30
Show GitHub Exploit DB Packet Storm
194 -
5.0
MEDIUM Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers … NVD-CWE-Other
CVE-2008-3661 cpe:2.3:a:drupal:drupal:6.4:*
cpe:2.3:a:drupal:drupal:5.10:*
2026-04-23 09:35
2008-09-24
Show GitHub Exploit DB Packet Storm
195 -
4.3
MEDIUM Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2008-3740 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2008-08-28
Show GitHub Exploit DB Packet Storm
196 -
3.5
LOW The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks b… CWE-79
Cross-site Scripting
CVE-2008-3741 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2008-08-28
Show GitHub Exploit DB Packet Storm
197 -
6.5
MEDIUM Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an execu… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-3742 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2008-08-28
Show GitHub Exploit DB Packet Storm
198 -
5.8
MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token valid… CWE-352
 Origin Validation Error
CVE-2008-3743 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2008-08-28
Show GitHub Exploit DB Packet Storm
199 -
5.8
MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add… CWE-352
 Origin Validation Error
CVE-2008-3744 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2008-08-28
Show GitHub Exploit DB Packet Storm
200 -
5.5
MEDIUM The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-3745 cpe:2.3:a:drupal:drupal:6.3:*
cpe:2.3:a:drupal:drupal:6.2:*
cpe:2.3:a:drupal:drupal:6.1:*
cpe:2.3:a:drupal:dru…
2026-04-23 09:35
2008-08-28
Show GitHub Exploit DB Packet Storm