{"schema_version":1,"title":"drupal/drupal (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in drupal/drupal (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Drupal core Open Redirect vulnerability, was published on 15 May 2024.","url":"https://junglewise.ai/threats/technologies/drupal-drupal","json_url":"https://junglewise.ai/threats/technologies/drupal-drupal.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/drupal-drupal","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":31,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cvss":3.1,"slug":"drupal-core-open-redirect-vulnerability-60e73e5b","title":"Drupal core Open Redirect vulnerability","severity":"low","exploited":false,"published_at":"2024-05-15T21:01:39+00:00","url":"https://junglewise.ai/threats/drupal-core-open-redirect-vulnerability-60e73e5b"},{"cve":"CVE-2020-13662","cvss":3.1,"epss":0.0086,"slug":"cve-2020-13662-drupal-core-open-redirect-vulnerability","title":"Drupal Core Open Redirect vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T17:49:27+00:00","url":"https://junglewise.ai/threats/cve-2020-13662-drupal-core-open-redirect-vulnerability"},{"cve":"CVE-2010-3094","epss":0.0137,"slug":"cve-2010-3094-drupal-cross-site-scripting-vulnerability-via-actions-feature-and","title":"Drupal cross-site scripting vulnerability via actions feature and trigger module","severity":"info","exploited":false,"published_at":"2022-05-17T05:48:23+00:00","url":"https://junglewise.ai/threats/cve-2010-3094-drupal-cross-site-scripting-vulnerability-via-actions-feature-and"},{"cve":"CVE-2012-1589","epss":0.0136,"slug":"cve-2012-1589-drupal-open-redirect","title":"Drupal Open Redirect","severity":"info","exploited":false,"published_at":"2022-05-17T04:56:42+00:00","url":"https://junglewise.ai/threats/cve-2012-1589-drupal-open-redirect"},{"cve":"CVE-2012-2153","epss":0.0188,"slug":"cve-2012-2153-drupal-improper-access-restrictions","title":"Drupal improper access restrictions","severity":"info","exploited":false,"published_at":"2022-05-17T04:56:41+00:00","url":"https://junglewise.ai/threats/cve-2012-2153-drupal-improper-access-restrictions"},{"cve":"CVE-2013-6389","cvss":3.1,"epss":0.0121,"slug":"cve-2013-6389-drupal-has-open-redirect-vulnerability-in-the-overlay-module","title":"Drupal has open redirect vulnerability in the Overlay module","severity":"low","exploited":false,"published_at":"2022-05-17T04:55:08+00:00","url":"https://junglewise.ai/threats/cve-2013-6389-drupal-has-open-redirect-vulnerability-in-the-overlay-module"},{"cve":"CVE-2016-3166","cvss":3,"epss":0.0118,"slug":"cve-2016-3166-drupal-crlf-injection-vulnerability-in-the-drupal-set-header","title":"Drupal CRLF injection vulnerability in the drupal_set_header function","severity":"low","exploited":false,"published_at":"2022-05-17T03:57:20+00:00","url":"https://junglewise.ai/threats/cve-2016-3166-drupal-crlf-injection-vulnerability-in-the-drupal-set-header"},{"cve":"CVE-2016-3165","cvss":3,"epss":0.0136,"slug":"cve-2016-3165-drupal-form-api-ignores-access-restrictions-on-submit-buttons","title":"Drupal Form API ignores access restrictions on submit buttons","severity":"low","exploited":false,"published_at":"2022-05-17T03:57:19+00:00","url":"https://junglewise.ai/threats/cve-2016-3165-drupal-form-api-ignores-access-restrictions-on-submit-buttons"},{"cve":"CVE-2016-3167","cvss":3,"epss":0.0135,"slug":"cve-2016-3167-drupal-open-redirect-vulnerability-in-the-drupal-goto-function","title":"Drupal Open redirect vulnerability in the drupal_goto function","severity":"low","exploited":false,"published_at":"2022-05-17T03:56:54+00:00","url":"https://junglewise.ai/threats/cve-2016-3167-drupal-open-redirect-vulnerability-in-the-drupal-goto-function"},{"cve":"CVE-2016-3171","cvss":3,"epss":0.0319,"slug":"cve-2016-3171-drupal-arbitrary-code-execution","title":"Drupal arbitrary code execution","severity":"low","exploited":false,"published_at":"2022-05-17T03:55:47+00:00","url":"https://junglewise.ai/threats/cve-2016-3171-drupal-arbitrary-code-execution"},{"cve":"CVE-2016-7570","cvss":3,"epss":0.0168,"slug":"cve-2016-7570-drupal-users-without-administer-comments-can-set-comment","title":"Drupal Users without \"Administer comments\" can set comment visibility on nodes they can edit","severity":"low","exploited":false,"published_at":"2022-05-17T03:47:58+00:00","url":"https://junglewise.ai/threats/cve-2016-7570-drupal-users-without-administer-comments-can-set-comment"},{"cve":"CVE-2016-7571","cvss":3,"epss":0.0149,"slug":"cve-2016-7571-drupal-cross-site-scripting-xss-vulnerability","title":"Drupal Cross-site scripting (XSS) vulnerability","severity":"low","exploited":false,"published_at":"2022-05-17T03:47:57+00:00","url":"https://junglewise.ai/threats/cve-2016-7571-drupal-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2016-7572","cvss":3,"epss":0.0172,"slug":"cve-2016-7572-drupal-unprivileged-access-to-config-export","title":"Drupal Unprivileged access to config export","severity":"low","exploited":false,"published_at":"2022-05-17T03:47:57+00:00","url":"https://junglewise.ai/threats/cve-2016-7572-drupal-unprivileged-access-to-config-export"},{"cve":"CVE-2016-6212","cvss":3,"epss":0.0221,"slug":"cve-2016-6212-drupal-views-can-allow-unauthorized-users-to-see-statistics","title":"Drupal Views can allow unauthorized users to see Statistics information","severity":"low","exploited":false,"published_at":"2022-05-17T03:39:45+00:00","url":"https://junglewise.ai/threats/cve-2016-6212-drupal-views-can-allow-unauthorized-users-to-see-statistics"},{"cve":"CVE-2016-6211","cvss":3,"epss":0.0284,"slug":"cve-2016-6211-drupal-saving-user-accounts-can-sometimes-grant-the-user-all-roles","title":"Drupal Saving user accounts can sometimes grant the user all roles","severity":"low","exploited":false,"published_at":"2022-05-17T03:39:45+00:00","url":"https://junglewise.ai/threats/cve-2016-6211-drupal-saving-user-accounts-can-sometimes-grant-the-user-all-roles"},{"cve":"CVE-2016-9452","cvss":3,"epss":0.0172,"slug":"cve-2016-9452-drupal-denial-of-service-via-transliterate-mechanism","title":"Drupal Denial of service via transliterate mechanism","severity":"low","exploited":false,"published_at":"2022-05-17T03:38:38+00:00","url":"https://junglewise.ai/threats/cve-2016-9452-drupal-denial-of-service-via-transliterate-mechanism"},{"cve":"CVE-2016-9450","cvss":3,"epss":0.01,"slug":"cve-2016-9450-drupal-incorrect-cache-context-on-password-reset-page","title":"Drupal Incorrect cache context on password reset page","severity":"low","exploited":false,"published_at":"2022-05-17T03:38:33+00:00","url":"https://junglewise.ai/threats/cve-2016-9450-drupal-incorrect-cache-context-on-password-reset-page"},{"cve":"CVE-2017-6379","cvss":3,"epss":0.0078,"slug":"cve-2017-6379-drupal-cross-site-request-forgery-csrf","title":"Drupal Cross-Site Request Forgery (CSRF)","severity":"low","exploited":false,"published_at":"2022-05-17T02:30:08+00:00","url":"https://junglewise.ai/threats/cve-2017-6379-drupal-cross-site-request-forgery-csrf"},{"cve":"CVE-2008-4793","epss":0.0221,"slug":"cve-2008-4793-drupal-node-validation-bypass-in-the-node-module-api","title":"Drupal Node Validation Bypass in the node module API","severity":"info","exploited":false,"published_at":"2022-05-17T02:19:15+00:00","url":"https://junglewise.ai/threats/cve-2008-4793-drupal-node-validation-bypass-in-the-node-module-api"},{"cve":"CVE-2017-6932","cvss":3,"epss":0.0117,"slug":"cve-2017-6932-drupal-external-link-injection-vulnerability","title":"Drupal external link injection vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T03:36:17+00:00","url":"https://junglewise.ai/threats/cve-2017-6932-drupal-external-link-injection-vulnerability"},{"cve":"CVE-2017-6920","cvss":3,"epss":0.2048,"slug":"cve-2017-6920-drupal-pecl-yaml-parser-unsafe-object-handling","title":"Drupal PECL YAML parser unsafe object handling","severity":"low","exploited":false,"published_at":"2022-05-14T02:57:07+00:00","url":"https://junglewise.ai/threats/cve-2017-6920-drupal-pecl-yaml-parser-unsafe-object-handling"},{"cve":"CVE-2017-6931","cvss":3,"epss":0.0107,"slug":"cve-2017-6931-drupal-settings-tray-access-bypass","title":"Drupal Settings Tray access bypass","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:49+00:00","url":"https://junglewise.ai/threats/cve-2017-6931-drupal-settings-tray-access-bypass"},{"cve":"CVE-2017-6930","cvss":3,"epss":0.0129,"slug":"cve-2017-6930-drupal-access-bypass-vulnerability","title":"Drupal access bypass vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:48+00:00","url":"https://junglewise.ai/threats/cve-2017-6930-drupal-access-bypass-vulnerability"},{"cve":"CVE-2017-6928","cvss":3,"epss":0.0102,"slug":"cve-2017-6928-drupal-access-bypass-vulnerability","title":"Drupal access bypass vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:48+00:00","url":"https://junglewise.ai/threats/cve-2017-6928-drupal-access-bypass-vulnerability"},{"cve":"CVE-2017-6925","cvss":3,"epss":0.0302,"slug":"cve-2017-6925-drupal-entity-access-bypass-for-entities-that-do-not-have-uuids-or","title":"Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:48+00:00","url":"https://junglewise.ai/threats/cve-2017-6925-drupal-entity-access-bypass-for-entities-that-do-not-have-uuids-or"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"drupal/drupal (Packagist)","slug":"drupal-drupal","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://www.drupal.org","repo_url":"https://github.com/drupal/drupal","description":"Open-source content management system and web framework.","url":"https://junglewise.ai/threats/technologies/drupal-drupal"},"most_severe":[{"cve":"CVE-2013-6389","cvss":3.1,"epss":0.0121,"slug":"cve-2013-6389-drupal-has-open-redirect-vulnerability-in-the-overlay-module","title":"Drupal has open redirect vulnerability in the Overlay module","severity":"low","exploited":false,"published_at":"2022-05-17T04:55:08+00:00","url":"https://junglewise.ai/threats/cve-2013-6389-drupal-has-open-redirect-vulnerability-in-the-overlay-module"},{"cve":"CVE-2020-13662","cvss":3.1,"epss":0.0086,"slug":"cve-2020-13662-drupal-core-open-redirect-vulnerability","title":"Drupal Core Open Redirect vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T17:49:27+00:00","url":"https://junglewise.ai/threats/cve-2020-13662-drupal-core-open-redirect-vulnerability"},{"cvss":3.1,"slug":"drupal-core-open-redirect-vulnerability-60e73e5b","title":"Drupal core Open Redirect vulnerability","severity":"low","exploited":false,"published_at":"2024-05-15T21:01:39+00:00","url":"https://junglewise.ai/threats/drupal-core-open-redirect-vulnerability-60e73e5b"},{"cve":"CVE-2017-6920","cvss":3,"epss":0.2048,"slug":"cve-2017-6920-drupal-pecl-yaml-parser-unsafe-object-handling","title":"Drupal PECL YAML parser unsafe object handling","severity":"low","exploited":false,"published_at":"2022-05-14T02:57:07+00:00","url":"https://junglewise.ai/threats/cve-2017-6920-drupal-pecl-yaml-parser-unsafe-object-handling"},{"cve":"CVE-2017-6381","cvss":3,"epss":0.039,"slug":"cve-2017-6381-drupal-remote-code-execution","title":"Drupal Remote code execution","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:33+00:00","url":"https://junglewise.ai/threats/cve-2017-6381-drupal-remote-code-execution"},{"cve":"CVE-2016-3171","cvss":3,"epss":0.0319,"slug":"cve-2016-3171-drupal-arbitrary-code-execution","title":"Drupal arbitrary code execution","severity":"low","exploited":false,"published_at":"2022-05-17T03:55:47+00:00","url":"https://junglewise.ai/threats/cve-2016-3171-drupal-arbitrary-code-execution"},{"cve":"CVE-2017-6925","cvss":3,"epss":0.0302,"slug":"cve-2017-6925-drupal-entity-access-bypass-for-entities-that-do-not-have-uuids-or","title":"Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:48+00:00","url":"https://junglewise.ai/threats/cve-2017-6925-drupal-entity-access-bypass-for-entities-that-do-not-have-uuids-or"},{"cve":"CVE-2016-6211","cvss":3,"epss":0.0284,"slug":"cve-2016-6211-drupal-saving-user-accounts-can-sometimes-grant-the-user-all-roles","title":"Drupal Saving user accounts can sometimes grant the user all roles","severity":"low","exploited":false,"published_at":"2022-05-17T03:39:45+00:00","url":"https://junglewise.ai/threats/cve-2016-6211-drupal-saving-user-accounts-can-sometimes-grant-the-user-all-roles"},{"cve":"CVE-2016-6212","cvss":3,"epss":0.0221,"slug":"cve-2016-6212-drupal-views-can-allow-unauthorized-users-to-see-statistics","title":"Drupal Views can allow unauthorized users to see Statistics information","severity":"low","exploited":false,"published_at":"2022-05-17T03:39:45+00:00","url":"https://junglewise.ai/threats/cve-2016-6212-drupal-views-can-allow-unauthorized-users-to-see-statistics"},{"cve":"CVE-2017-6924","cvss":3,"epss":0.021,"slug":"cve-2017-6924-drupal-rest-api-can-bypass-comment-approval","title":"Drupal REST API can bypass comment approval","severity":"low","exploited":false,"published_at":"2022-05-13T01:36:23+00:00","url":"https://junglewise.ai/threats/cve-2017-6924-drupal-rest-api-can-bypass-comment-approval"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}