{"schema_version":1,"title":"Packagist:Https://Packages.drupal.org/8 Drupal/Ai vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in Packagist:Https://Packages.drupal.org/8 Drupal/Ai: 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84912, was published on 2 September 2026.","url":"https://junglewise.ai/threats/technologies/drupal-ai","json_url":"https://junglewise.ai/threats/technologies/drupal-ai.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/drupal-ai","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":10,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":4,"last_365_days":6},"latest":[{"cve":"CVE-2026-84912","slug":"cve-2026-84912-drupal-contrib-2026-120-this-submodule-ai-translate-enables-you","title":"Drupal AI module access bypass in translation","severity":"info","exploited":false,"published_at":"2026-09-02T16:27:29+00:00","url":"https://junglewise.ai/threats/cve-2026-84912-drupal-contrib-2026-120-this-submodule-ai-translate-enables-you"},{"cve":"CVE-2026-84911","slug":"cve-2026-84911-drupal-contrib-2026-119-this-ai-chatbot-module-enables-you-to","title":"Drupal AI module cross-site scripting in legacy agent setup","severity":"info","exploited":false,"published_at":"2026-09-02T16:26:41+00:00","url":"https://junglewise.ai/threats/cve-2026-84911-drupal-contrib-2026-119-this-ai-chatbot-module-enables-you-to"},{"cve":"CVE-2026-13235","cvss":4.2,"epss":0.0021,"slug":"cve-2026-13235-drupal-ai-missing-authorization-in-agent-tools","title":"Drupal AI missing authorization in agent tools","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:39.597+00:00","url":"https://junglewise.ai/threats/cve-2026-13235-drupal-ai-missing-authorization-in-agent-tools"},{"cve":"CVE-2026-13234","cvss":5.4,"epss":0.0025,"slug":"cve-2026-13234-drupal-ai-module-cross-site-scripting-and-information-disclosure","title":"Drupal AI module cross-site scripting and information disclosure","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:39.5+00:00","url":"https://junglewise.ai/threats/cve-2026-13234-drupal-ai-module-cross-site-scripting-and-information-disclosure"},{"cve":"CVE-2026-3573","epss":0.0039,"slug":"cve-2026-3573-drupal-contrib-2026-028-the-module-and-certain-submodules-ai","title":"DRUPAL-CONTRIB-2026-028 - The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM t","severity":"info","exploited":false,"published_at":"2026-03-11T16:33:14+00:00","url":"https://junglewise.ai/threats/cve-2026-3573-drupal-contrib-2026-028-the-module-and-certain-submodules-ai"},{"cve":"CVE-2025-13981","epss":0.0014,"slug":"cve-2025-13981-drupal-contrib-2025-119-this-modules-provides-the-ability-to-chat","title":"DRUPAL-CONTRIB-2025-119 - This modules provides the ability to chat with an AI Agent using a large-language model (LLM) provider for different purposes. The module d","severity":"info","exploited":false,"published_at":"2025-12-03T18:48:23+00:00","url":"https://junglewise.ai/threats/cve-2025-13981-drupal-contrib-2025-119-this-modules-provides-the-ability-to-chat"},{"cve":"CVE-2025-31692","cvss":4,"epss":0.0076,"slug":"cve-2025-31692-drupal-contrib-2025-021-the-ai-automators-module-a-submodule-of","title":"Drupal AI Vulnerable to OS Command Injection via Optional Automator Types","severity":"medium","exploited":false,"published_at":"2025-04-01T00:30:35+00:00","url":"https://junglewise.ai/threats/cve-2025-31692-drupal-contrib-2025-021-the-ai-automators-module-a-submodule-of"},{"cve":"CVE-2025-31693","cvss":3.1,"epss":0.0075,"slug":"cve-2025-31693-drupal-contrib-2025-022-the-ai-automators-module-a-submodule-of","title":"Drupal AI Vulnerable to OS Command Injection","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-31693-drupal-contrib-2025-022-the-ai-automators-module-a-submodule-of"},{"cve":"CVE-2025-31677","cvss":3.1,"epss":0.0022,"slug":"cve-2025-31677-drupal-contrib-2025-003-the-drupal-ai-module-provides-a-framework","title":"Drupal AI Cross-Site Request Forgery (CSRF) vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:33+00:00","url":"https://junglewise.ai/threats/cve-2025-31677-drupal-contrib-2025-003-the-drupal-ai-module-provides-a-framework"},{"cve":"CVE-2025-31678","cvss":3.1,"epss":0.0037,"slug":"cve-2025-31678-drupal-contrib-2025-004-the-ai-logging-sub-module-enables-you-to","title":"Drupal AI Missing Authorization vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:33+00:00","url":"https://junglewise.ai/threats/cve-2025-31678-drupal-contrib-2025-004-the-ai-logging-sub-module-enables-you-to"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Webform","slug":"drupal-webform","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/drupal-webform"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Social","slug":"drupal-social","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/drupal-social"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml","slug":"drupal-miniorange-saml","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-saml"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Jsonapi","slug":"drupal-jsonapi","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-jsonapi"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange 2fa","slug":"drupal-miniorange-2fa","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/drupal-miniorange-2fa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Facets","slug":"drupal-facets","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-facets"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Permissions By Term","slug":"drupal-permissions-by-term","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-permissions-by-term"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Tfa","slug":"drupal-tfa","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/drupal-tfa"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Apigee Edge","slug":"drupal-apigee-edge","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-apigee-edge"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cleantalk","slug":"drupal-cleantalk","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cleantalk"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Commerce","slug":"drupal-commerce","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-commerce"},{"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Cookies","slug":"drupal-cookies","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/drupal-cookies"}],"technology":{"hub":true,"name":"Packagist:Https://Packages.drupal.org/8 Drupal/Ai","slug":"drupal-ai","vendor":{"name":"Packagist:Https://Packages.drupal.org/8","slug":"packagist-https-packages-drupal-org-8","url":"https://junglewise.ai/threats/vendors/packagist-https-packages-drupal-org-8"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/drupal-ai"},"most_severe":[{"cve":"CVE-2025-31692","cvss":4,"epss":0.0076,"slug":"cve-2025-31692-drupal-contrib-2025-021-the-ai-automators-module-a-submodule-of","title":"Drupal AI Vulnerable to OS Command Injection via Optional Automator Types","severity":"medium","exploited":false,"published_at":"2025-04-01T00:30:35+00:00","url":"https://junglewise.ai/threats/cve-2025-31692-drupal-contrib-2025-021-the-ai-automators-module-a-submodule-of"},{"cve":"CVE-2025-31693","cvss":3.1,"epss":0.0075,"slug":"cve-2025-31693-drupal-contrib-2025-022-the-ai-automators-module-a-submodule-of","title":"Drupal AI Vulnerable to OS Command Injection","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-31693-drupal-contrib-2025-022-the-ai-automators-module-a-submodule-of"},{"cve":"CVE-2025-31678","cvss":3.1,"epss":0.0037,"slug":"cve-2025-31678-drupal-contrib-2025-004-the-ai-logging-sub-module-enables-you-to","title":"Drupal AI Missing Authorization vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:33+00:00","url":"https://junglewise.ai/threats/cve-2025-31678-drupal-contrib-2025-004-the-ai-logging-sub-module-enables-you-to"},{"cve":"CVE-2025-31677","cvss":3.1,"epss":0.0022,"slug":"cve-2025-31677-drupal-contrib-2025-003-the-drupal-ai-module-provides-a-framework","title":"Drupal AI Cross-Site Request Forgery (CSRF) vulnerability","severity":"low","exploited":false,"published_at":"2025-04-01T00:30:33+00:00","url":"https://junglewise.ai/threats/cve-2025-31677-drupal-contrib-2025-003-the-drupal-ai-module-provides-a-framework"},{"cve":"CVE-2026-13234","cvss":5.4,"epss":0.0025,"slug":"cve-2026-13234-drupal-ai-module-cross-site-scripting-and-information-disclosure","title":"Drupal AI module cross-site scripting and information disclosure","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:39.5+00:00","url":"https://junglewise.ai/threats/cve-2026-13234-drupal-ai-module-cross-site-scripting-and-information-disclosure"},{"cve":"CVE-2026-13235","cvss":4.2,"epss":0.0021,"slug":"cve-2026-13235-drupal-ai-missing-authorization-in-agent-tools","title":"Drupal AI missing authorization in agent tools","severity":"info","exploited":false,"published_at":"2026-07-10T22:16:39.597+00:00","url":"https://junglewise.ai/threats/cve-2026-13235-drupal-ai-missing-authorization-in-agent-tools"},{"cve":"CVE-2026-3573","epss":0.0039,"slug":"cve-2026-3573-drupal-contrib-2026-028-the-module-and-certain-submodules-ai","title":"DRUPAL-CONTRIB-2026-028 - The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM t","severity":"info","exploited":false,"published_at":"2026-03-11T16:33:14+00:00","url":"https://junglewise.ai/threats/cve-2026-3573-drupal-contrib-2026-028-the-module-and-certain-submodules-ai"},{"cve":"CVE-2025-13981","epss":0.0014,"slug":"cve-2025-13981-drupal-contrib-2025-119-this-modules-provides-the-ability-to-chat","title":"DRUPAL-CONTRIB-2025-119 - This modules provides the ability to chat with an AI Agent using a large-language model (LLM) provider for different purposes. The module d","severity":"info","exploited":false,"published_at":"2025-12-03T18:48:23+00:00","url":"https://junglewise.ai/threats/cve-2025-13981-drupal-contrib-2025-119-this-modules-provides-the-ability-to-chat"},{"cve":"CVE-2026-84912","slug":"cve-2026-84912-drupal-contrib-2026-120-this-submodule-ai-translate-enables-you","title":"Drupal AI module access bypass in translation","severity":"info","exploited":false,"published_at":"2026-09-02T16:27:29+00:00","url":"https://junglewise.ai/threats/cve-2026-84912-drupal-contrib-2026-120-this-submodule-ai-translate-enables-you"},{"cve":"CVE-2026-84911","slug":"cve-2026-84911-drupal-contrib-2026-119-this-ai-chatbot-module-enables-you-to","title":"Drupal AI module cross-site scripting in legacy agent setup","severity":"info","exploited":false,"published_at":"2026-09-02T16:26:41+00:00","url":"https://junglewise.ai/threats/cve-2026-84911-drupal-contrib-2026-119-this-ai-chatbot-module-enables-you-to"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}