{"schema_version":1,"title":"Drupal Ajenti Core vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in Drupal Ajenti Core: 0 in the last 7 days and 2 in the last 90 days, 5 of them critical and 4 exploited in the wild. The most recent, CVE-2026-15980, was published on 30 August 2026.","url":"https://junglewise.ai/threats/technologies/core","json_url":"https://junglewise.ai/threats/technologies/core.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/core","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":8,"critical":5,"exploited":4,"last_7_days":0,"last_30_days":1,"last_90_days":2,"last_365_days":5},"latest":[{"cve":"CVE-2026-15980","cvss":9.8,"epss":0.0045,"slug":"cve-2026-15980-myhome-core-authentication-bypass-in-ajax-handler","title":"MyHome Core authentication bypass in AJAX handler","severity":"critical","exploited":false,"published_at":"2026-08-30T05:16:58.407+00:00","url":"https://junglewise.ai/threats/cve-2026-15980-myhome-core-authentication-bypass-in-ajax-handler"},{"cve":"CVE-2026-32333","cvss":7.1,"epss":0.0025,"slug":"cve-2026-32333-mayosis-core-reflected-cross-site-scripting-xss","title":"Mayosis Core reflected cross-site scripting (XSS)","severity":"high","exploited":false,"published_at":"2026-08-18T14:17:03.133+00:00","url":"https://junglewise.ai/threats/cve-2026-32333-mayosis-core-reflected-cross-site-scripting-xss"},{"cve":"CVE-2026-9082","cvss":9.8,"epss":0.157,"slug":"cve-2026-9082-drupal-drupal-core-sql-injection-in-database-abstraction-api","title":"Drupal Drupal core SQL injection in database abstraction API","severity":"critical","exploited":true,"published_at":"2026-05-20T20:16:41.23+00:00","url":"https://junglewise.ai/threats/cve-2026-9082-drupal-drupal-core-sql-injection-in-database-abstraction-api"},{"cve":"CVE-2026-27621","cvss":4,"epss":0.0027,"slug":"cve-2026-27621-typicms-core-stored-xss-via-svg-file-upload","title":"TypiCMS Core stored XSS via SVG file upload","severity":"medium","exploited":false,"published_at":"2026-02-25T16:06:59+00:00","url":"https://junglewise.ai/threats/cve-2026-27621-typicms-core-stored-xss-via-svg-file-upload"},{"cve":"CVE-2025-64767","cvss":3.1,"epss":0.0021,"slug":"cve-2025-64767-hpke-core-aead-nonce-reuse-in-sendercontext","title":"@hpke/core AEAD nonce reuse in SenderContext","severity":"low","exploited":false,"published_at":"2025-11-20T17:36:13+00:00","url":"https://junglewise.ai/threats/cve-2025-64767-hpke-core-aead-nonce-reuse-in-sendercontext"},{"cve":"CVE-2018-7602","cvss":3.1,"epss":0.9921,"slug":"cve-2018-7602-drupal-core-remote-code-execution-vulnerability","title":"Drupal Core Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2024-04-23T22:36:09+00:00","url":"https://junglewise.ai/threats/cve-2018-7602-drupal-core-remote-code-execution-vulnerability"},{"cve":"CVE-2019-6340","cvss":3,"epss":0.9202,"slug":"cve-2019-6340-drupal-core-remote-code-execution-vulnerability","title":"Drupal Core Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-13T01:22:41+00:00","url":"https://junglewise.ai/threats/cve-2019-6340-drupal-core-remote-code-execution-vulnerability"},{"cve":"CVE-2020-36193","cvss":3.1,"epss":0.706,"slug":"cve-2020-36193-pear-archive-tar-improper-link-resolution-vulnerability","title":"Directory Traversal in Archive_Tar","severity":"critical","exploited":true,"published_at":"2021-04-22T16:20:36+00:00","url":"https://junglewise.ai/threats/cve-2020-36193-pear-archive-tar-improper-link-resolution-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Drupal Webform","slug":"webform","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/webform"},{"name":"Drupal Core","slug":"drupal-core","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/drupal-core"},{"name":"Drupal","slug":"drupal","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/drupal"},{"name":"Drupal Gammu SMS Daemon","slug":"gammu-sms-daemon","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/gammu-sms-daemon"}],"technology":{"hub":true,"name":"Drupal Ajenti Core","slug":"core","vendor":{"name":"Drupal","slug":"drupal","url":"https://junglewise.ai/threats/vendors/drupal"},"aliases":[],"category":"library","homepage":"https://ajenti.org/","repo_url":"https://github.com/ajenti/ajenti","description":"The core plugin and framework for the Ajenti server administration panel.","url":"https://junglewise.ai/threats/technologies/core"},"most_severe":[{"cve":"CVE-2026-9082","cvss":9.8,"epss":0.157,"slug":"cve-2026-9082-drupal-drupal-core-sql-injection-in-database-abstraction-api","title":"Drupal Drupal core SQL injection in database abstraction API","severity":"critical","exploited":true,"published_at":"2026-05-20T20:16:41.23+00:00","url":"https://junglewise.ai/threats/cve-2026-9082-drupal-drupal-core-sql-injection-in-database-abstraction-api"},{"cve":"CVE-2018-7602","cvss":3.1,"epss":0.9921,"slug":"cve-2018-7602-drupal-core-remote-code-execution-vulnerability","title":"Drupal Core Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2024-04-23T22:36:09+00:00","url":"https://junglewise.ai/threats/cve-2018-7602-drupal-core-remote-code-execution-vulnerability"},{"cve":"CVE-2020-36193","cvss":3.1,"epss":0.706,"slug":"cve-2020-36193-pear-archive-tar-improper-link-resolution-vulnerability","title":"Directory Traversal in Archive_Tar","severity":"critical","exploited":true,"published_at":"2021-04-22T16:20:36+00:00","url":"https://junglewise.ai/threats/cve-2020-36193-pear-archive-tar-improper-link-resolution-vulnerability"},{"cve":"CVE-2019-6340","cvss":3,"epss":0.9202,"slug":"cve-2019-6340-drupal-core-remote-code-execution-vulnerability","title":"Drupal Core Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-13T01:22:41+00:00","url":"https://junglewise.ai/threats/cve-2019-6340-drupal-core-remote-code-execution-vulnerability"},{"cve":"CVE-2026-15980","cvss":9.8,"epss":0.0045,"slug":"cve-2026-15980-myhome-core-authentication-bypass-in-ajax-handler","title":"MyHome Core authentication bypass in AJAX handler","severity":"critical","exploited":false,"published_at":"2026-08-30T05:16:58.407+00:00","url":"https://junglewise.ai/threats/cve-2026-15980-myhome-core-authentication-bypass-in-ajax-handler"},{"cve":"CVE-2026-32333","cvss":7.1,"epss":0.0025,"slug":"cve-2026-32333-mayosis-core-reflected-cross-site-scripting-xss","title":"Mayosis Core reflected cross-site scripting (XSS)","severity":"high","exploited":false,"published_at":"2026-08-18T14:17:03.133+00:00","url":"https://junglewise.ai/threats/cve-2026-32333-mayosis-core-reflected-cross-site-scripting-xss"},{"cve":"CVE-2026-27621","cvss":4,"epss":0.0027,"slug":"cve-2026-27621-typicms-core-stored-xss-via-svg-file-upload","title":"TypiCMS Core stored XSS via SVG file upload","severity":"medium","exploited":false,"published_at":"2026-02-25T16:06:59+00:00","url":"https://junglewise.ai/threats/cve-2026-27621-typicms-core-stored-xss-via-svg-file-upload"},{"cve":"CVE-2025-64767","cvss":3.1,"epss":0.0021,"slug":"cve-2025-64767-hpke-core-aead-nonce-reuse-in-sendercontext","title":"@hpke/core AEAD nonce reuse in SenderContext","severity":"low","exploited":false,"published_at":"2025-11-20T17:36:13+00:00","url":"https://junglewise.ai/threats/cve-2025-64767-hpke-core-aead-nonce-reuse-in-sendercontext"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}