Technology · Packagist
drupal/drupal (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 31 vulnerabilities in drupal/drupal (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Drupal core Open Redirect vulnerability, was published on 15 May 2024.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About drupal/drupal (Packagist)
Open-source content management system and web framework.
Latest drupal/drupal (Packagist) vulnerabilities
- Drupal core Open Redirect vulnerabilitylowCVSS 3.1
- CVE-2020-13662: Drupal Core Open Redirect vulnerabilitylowCVSS 3.1EPSS 0.9%
- CVE-2010-3094: Drupal cross-site scripting vulnerability via actions feature and trigger moduleinfoEPSS 1.4%
- CVE-2012-1589: Drupal Open RedirectinfoEPSS 1.4%
- CVE-2012-2153: Drupal improper access restrictionsinfoEPSS 1.9%
- CVE-2013-6389: Drupal has open redirect vulnerability in the Overlay modulelowCVSS 3.1EPSS 1.2%
- CVE-2016-3166: Drupal CRLF injection vulnerability in the drupal_set_header functionlowCVSS 3EPSS 1.2%
- CVE-2016-3165: Drupal Form API ignores access restrictions on submit buttonslowCVSS 3EPSS 1.4%
- CVE-2016-3167: Drupal Open redirect vulnerability in the drupal_goto functionlowCVSS 3EPSS 1.4%
- CVE-2016-3171: Drupal arbitrary code executionlowCVSS 3EPSS 3.2%
- CVE-2016-7570: Drupal Users without "Administer comments" can set comment visibility on nodes they can editlowCVSS 3EPSS 1.7%
- CVE-2016-7571: Drupal Cross-site scripting (XSS) vulnerabilitylowCVSS 3EPSS 1.5%
- CVE-2016-7572: Drupal Unprivileged access to config exportlowCVSS 3EPSS 1.7%
- CVE-2016-6212: Drupal Views can allow unauthorized users to see Statistics informationlowCVSS 3EPSS 2.2%
- CVE-2016-6211: Drupal Saving user accounts can sometimes grant the user all roleslowCVSS 3EPSS 2.8%
- CVE-2016-9452: Drupal Denial of service via transliterate mechanismlowCVSS 3EPSS 1.7%
- CVE-2016-9450: Drupal Incorrect cache context on password reset pagelowCVSS 3EPSS 1.0%
- CVE-2017-6379: Drupal Cross-Site Request Forgery (CSRF)lowCVSS 3EPSS 0.8%
- CVE-2008-4793: Drupal Node Validation Bypass in the node module APIinfoEPSS 2.2%
- CVE-2017-6932: Drupal external link injection vulnerabilitylowCVSS 3EPSS 1.2%
- CVE-2017-6920: Drupal PECL YAML parser unsafe object handlinglowCVSS 3EPSS 20.5%
- CVE-2017-6931: Drupal Settings Tray access bypasslowCVSS 3EPSS 1.1%
- CVE-2017-6930: Drupal access bypass vulnerabilitylowCVSS 3EPSS 1.3%
- CVE-2017-6928: Drupal access bypass vulnerabilitylowCVSS 3EPSS 1.0%
- CVE-2017-6925: Drupal Entity access bypass for entities that do not have UUIDs or have protected revisionslowCVSS 3EPSS 3.0%
Most severe drupal/drupal (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2013-6389: Drupal has open redirect vulnerability in the Overlay modulelowCVSS 3.1EPSS 1.2%
- CVE-2020-13662: Drupal Core Open Redirect vulnerabilitylowCVSS 3.1EPSS 0.9%
- Drupal core Open Redirect vulnerabilitylowCVSS 3.1
- CVE-2017-6920: Drupal PECL YAML parser unsafe object handlinglowCVSS 3EPSS 20.5%
- CVE-2017-6381: Drupal Remote code executionlowCVSS 3EPSS 3.9%
- CVE-2016-3171: Drupal arbitrary code executionlowCVSS 3EPSS 3.2%
- CVE-2017-6925: Drupal Entity access bypass for entities that do not have UUIDs or have protected revisionslowCVSS 3EPSS 3.0%
- CVE-2016-6211: Drupal Saving user accounts can sometimes grant the user all roleslowCVSS 3EPSS 2.8%
- CVE-2016-6212: Drupal Views can allow unauthorized users to see Statistics informationlowCVSS 3EPSS 2.2%
- CVE-2017-6924: Drupal REST API can bypass comment approvallowCVSS 3EPSS 2.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/drupal-drupal.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "drupal/drupal (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/drupal-drupal, 28 September 2026.