Vendor
Drupal vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 86 vulnerabilities in Drupal: 0 in the last 7 days and 64 in the last 90 days, 10 of them critical and 6 exploited in the wild. The most recent, CVE-2026-81205, was published on 2 September 2026. 4 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 64
- Critical, all time
- 10
- Exploited in the wild
- 6
About Drupal
An open-source content management framework written in PHP.
Drupal technologies
Latest Drupal vulnerabilities
- CVE-2026-81205: Drupal LDAP/Active Directory Integration LDAP injectionmediumCVSS 5.3EPSS 0.3%
- CVE-2026-81164: Drupal Entity PDF missing authorization in PDF viewmediumCVSS 5.4EPSS 0.2%
- CVE-2026-81160: Drupal Slick Carousel stored XSS in UI option setsmediumCVSS 6.1EPSS 0.3%
- CVE-2026-81158: Drupal Entity API incorrect authorization in JSON:API endpointsmediumCVSS 5.3EPSS 0.3%
- CVE-2026-76782: Drupal Screenshot unsupported security issuehighCVSS 7.3EPSS 0.3%
- CVE-2026-76759: Drupal Screenshot unsupported security issuehighCVSS 7.3EPSS 0.3%
- CVE-2026-76758: Drupal Link content parser unsupported security vulnerabilitymediumCVSS 5.9EPSS 0.4%
- CVE-2026-76757: Drupal Gammu SMS Daemon authorization token disclosuremediumCVSS 5.9EPSS 0.4%
- CVE-2026-76756: Drupal Gammu SMS Daemon timing attack in REST API authenticationmediumCVSS 5.9EPSS 0.4%
- CVE-2026-76755: Drupal Gammu SMS Daemon OS command injectionmediumCVSS 5.9EPSS 0.4%
- CVE-2026-55805: Drupal stored cross-site scripting in Layout BuildermediumCVSS 5.4EPSS 0.2%
- CVE-2026-18985: Drupal Edit in-place field authorization bypasshighCVSS 8.1EPSS 0.2%
- CVE-2026-18261: Drupal Powerful Surveys unsupported with unfixed security issuemediumCVSS 5.7EPSS 0.2%
- CVE-2026-18259: Drupal Token Content Access timing attack in token comparisonhighCVSS 7.5EPSS 0.3%
- CVE-2026-16645: Drupal PhotoSwipe authorization bypass in image gallery displaycriticalCVSS 9.1EPSS 0.2%
- CVE-2026-16644: Drupal Webform REST access bypass in permission checkscriticalCVSS 9.1EPSS 0.3%
- CVE-2026-16643: Drupal Lunr exposed filters security issuemediumCVSS 5.7EPSS 0.2%
- CVE-2026-16642: Drupal Email Login OTP brute force protection bypassmediumCVSS 5.7EPSS 0.2%
- CVE-2026-16641: Drupal Commerce Elavon payment module unsupported due to unpatched security vulnerabilitycriticalCVSS 9.8EPSS 0.3%
- CVE-2026-16640: Drupal Search API Autocomplete reflected XSS in test scriptmediumCVSS 6.1EPSS 0.1%
- CVE-2026-16639: Drupal Internationalization Single Sign-On authentication bypass in token validationcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-16638: Drupal Media Folders stored cross-site scriptingmediumCVSS 6.1EPSS 0.1%
- CVE-2026-15917: Drupal core cross-site scripting in HTMX attribute sanitizationmediumCVSS 4.7EPSS 0.1%
- CVE-2026-15916: Drupal core missing authorization in image derivativesmediumCVSS 4.2EPSS 0.1%
- CVE-2026-15088: Drupal Development Environment unsupported security issuemediumCVSS 5.7EPSS 0.2%
Most severe Drupal vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-9082: Drupal Drupal core SQL injection in database abstraction APIcriticalexploited in the wildCVSS 9.8EPSS 33.7%
- CVE-2018-7602: Drupal Core Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2018-7600: Drupal Core Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-13671: Drupal core Un-restricted Upload of Filecriticalexploited in the wildCVSS 8.8
- CVE-2019-6340: Drupal Core Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.1
- CVE-2020-36193: PEAR Archive_Tar Improper Link Resolution Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2026-16639: Drupal Internationalization Single Sign-On authentication bypass in token validationcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-16641: Drupal Commerce Elavon payment module unsupported due to unpatched security vulnerabilitycriticalCVSS 9.8EPSS 0.3%
- CVE-2026-16644: Drupal Webform REST access bypass in permission checkscriticalCVSS 9.1EPSS 0.3%
- CVE-2026-16645: Drupal PhotoSwipe authorization bypass in image gallery displaycriticalCVSS 9.1EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 37 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 15 | 4 | |
| 31 Aug 2026 | 10 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/drupal.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Drupal vulnerabilities", https://junglewise.ai/threats/vendors/drupal, 26 September 2026.