Vendor
Packagist:Https://Packages.drupal.org/8 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 609 vulnerabilities in Packagist:Https://Packages.drupal.org/8: 36 in the last 7 days and 147 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96382, was published on 23 September 2026. 31 technologies have a page of their own.
- Last 7 days
- 36
- Last 90 days
- 147
- Critical, all time
- 5
- Exploited in the wild
- 0
Packagist:Https://Packages.drupal.org/8 technologies
- Packagist:Https://Packages.drupal.org/8 Drupal/Webform31
- Packagist:Https://Packages.drupal.org/8 Drupal/Social16
- Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange Saml15
- Packagist:Https://Packages.drupal.org/8 Drupal/Ai10
- Packagist:Https://Packages.drupal.org/8 Drupal/Jsonapi6
- Packagist:Https://Packages.drupal.org/8 Drupal/Miniorange 2fa6
- Packagist:Https://Packages.drupal.org/8 Drupal/Facets5
- Packagist:Https://Packages.drupal.org/8 Drupal/Permissions By Term5
- Packagist:Https://Packages.drupal.org/8 Drupal/Tfa5
- Packagist:Https://Packages.drupal.org/8 Drupal/Apigee Edge4
- Packagist:Https://Packages.drupal.org/8 Drupal/Cleantalk4
- Packagist:Https://Packages.drupal.org/8 Drupal/Commerce4
- Packagist:Https://Packages.drupal.org/8 Drupal/Cookies4
- Packagist:Https://Packages.drupal.org/8 Drupal/Graphql4
- Packagist:Https://Packages.drupal.org/8 Drupal/Group4
- Packagist:Https://Packages.drupal.org/8 Drupal/Gutenberg4
- Packagist:Https://Packages.drupal.org/8 Drupal/Mail Login4
- Packagist:Https://Packages.drupal.org/8 Drupal/Openid Connect4
- Packagist:Https://Packages.drupal.org/8 Drupal/Opigno Learning Path4
- Packagist:Https://Packages.drupal.org/8 Drupal/Paragraphs4
- Packagist:Https://Packages.drupal.org/8 Drupal/Tacjs4
- Packagist:Https://Packages.drupal.org/8 Drupal/Tagify4
- Packagist:Https://Packages.drupal.org/8 Drupal/Tb Megamenu4
- Packagist:Https://Packages.drupal.org/8 Drupal/Canvas4
- Packagist:Https://Packages.drupal.org/8 Drupal/Addtoany3
- Packagist:Https://Packages.drupal.org/8 Drupal/Alogin3
- Packagist:Https://Packages.drupal.org/8 Drupal/Disable Login3
- Packagist:Https://Packages.drupal.org/8 Drupal/Login Disable3
- Packagist:Https://Packages.drupal.org/8 Drupal/Monster Menus3
- Packagist:Https://Packages.drupal.org/8 Drupal/One Time Password3
- Packagist:Https://Packages.drupal.org/8 Drupal/Svg Formatter3
Latest Packagist:Https://Packages.drupal.org/8 vulnerabilities
- CVE-2026-96382: Diba Carousel Slider cross-site scripting in HTML descriptioninfo
- CVE-2026-96386: Drupal Smart Content access bypass in AJAX endpointinfo
- CVE-2026-96380: Drupal CSS Usage Analyzer improper access control on save endpointinfo
- CVE-2026-96377: Drupal Combined Image Style insufficient validation in image derivativesinfo
- CVE-2026-96392: Drupal AI CKEditor Twig template injectioninfo
- CVE-2026-96391: Drupal Webform REST module access bypass in permission checksinfo
- CVE-2026-96390: Drupal Editoria11y permission access bypassinfo
- CVE-2026-96388: Drupal Tawk.to module CSRF vulnerabilityinfo
- CVE-2026-96387: Stop Administrator Login access bypass across authentication mechanismsinfo
- CVE-2026-96385: Drupal REST & JSON API Authentication access bypassinfo
- CVE-2026-96379: Drupal Cookiecuttr module stored XSS in administration forminfo
- CVE-2026-96384: Drupal Mermaid Diagram Field access bypassinfo
- CVE-2026-96378: Drupal Commerce Decoupled Checkout access bypass in REST endpointinfo
- CVE-2026-96374: Drupal Project Browser CSRF in admin actionsinfo
- CVE-2026-96376: Drupal Cloud module command injection in Kubernetes integrationinfo
- CVE-2026-96375: Drupal Cloud module TLS certificate validation bypassinfo
- CVE-2026-96355: Drupal Webform template injection in token replacementinfo
- CVE-2026-96356: Drupal Webform access control bypass with malformed configurationinfo
- CVE-2026-96398: Drupal Webform module access bypass in submission view modesinfo
- CVE-2026-96357: Drupal Webform module cross-site scripting in file download handlinginfo
- CVE-2026-96364: Drupal Webform anti-spam bypass in Share submoduleinfo
- CVE-2026-96365: Drupal Webform denial of service via unvalidated token parameterinfo
- CVE-2026-96366: Drupal Webform module insufficient file upload validationinfo
- CVE-2026-96373: Drupal Webform access bypass in export filename validationinfo
- CVE-2026-96372: Drupal Webform module insufficient access restriction on remote HTTP operationsinfo
Most severe Packagist:Https://Packages.drupal.org/8 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-16639: Drupal Internationalization Single Sign-On authentication bypass in token validationcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-16641: Drupal Commerce Elavon payment module unsupported due to unpatched security vulnerabilitycriticalCVSS 9.8EPSS 0.3%
- CVE-2026-73475: Drupal Commerce PayPal access bypass in Payflow LinkcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-16644: Drupal Webform REST access bypass in permission checkscriticalCVSS 9.1EPSS 0.3%
- CVE-2026-16645: Drupal PhotoSwipe authorization bypass in image gallery displaycriticalCVSS 9.1EPSS 0.2%
- CVE-2026-18985: Drupal Edit in-place field authorization bypasshighCVSS 8.1EPSS 0.2%
- CVE-2026-18259: Drupal Token Content Access timing attack in token comparisonhighCVSS 7.5EPSS 0.3%
- CVE-2026-76759: Drupal Screenshot unsupported security issuehighCVSS 7.3EPSS 0.3%
- CVE-2026-81201: Drupal Monster Menus stored cross-site scripting in page titlesmediumCVSS 6.1EPSS 0.3%
- CVE-2026-81160: Drupal Slick Carousel stored XSS in UI option setsmediumCVSS 6.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 41 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 12 | 4 | |
| 31 Aug 2026 | 39 | 1 | |
| 7 Sep 2026 | 19 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 36 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/packagist-https-packages-drupal-org-8.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Packagist:Https://Packages.drupal.org/8 vulnerabilities", https://junglewise.ai/threats/vendors/packagist-https-packages-drupal-org-8, 27 September 2026.