Where
-Infinity
0

Drupal DrupalThe Image module allows you to define and configure image fields. The module doesn't sufficiently ch…

Risk 42
Severity
9
First published (updated )

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )

Drupal Mother May IMother May I - Critical - Unsupported - SA-CONTRIB-2026-045

Risk 86
Severity
9.8
First published (updated )

Drupal Clean RESTfulClean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078

Risk 45
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal DrupalDrupal core - Moderately critical - Improper validation - SA-CORE-2026-009

Risk 34
Severity
5.4
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Risk 17
Severity
3.1
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Gadget chain - SA-CORE-2026-006

Risk 45
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007

Risk 35
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Critical - PHP object injection - SA-CORE-2026-005

Risk 45
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Location SelectorLocation Selector - Critical - SQL Injection - SA-CONTRIB-2026-072

Risk 56
Severity
7.4
First published (updated )

Drupal Ray Enterprise TranslationRay Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071

Risk 22
Severity
4.3
First published (updated )

Drupal ColorboxColorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069

Risk 34
Severity
5.4
First published (updated )

Drupal FlowDropFlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068

Risk 34
Severity
5.4
First published (updated )

Drupal FlowDropFlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Canvas Project Drupal Canvas DrupalDrupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065

Risk 38
Severity
6.1
First published (updated )

Drupal Canvas Project Drupal Canvas DrupalDrupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066

Risk 38
Severity
6.1
First published (updated )

Drupal ParagraphsParagraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061

Risk 40
Severity
6.5
First published (updated )

Drupal ParagraphsParagraphs - Less critical - Access bypass - SA-CONTRIB-2026-060

Risk 40
Severity
6.5
First published (updated )

Artificial Intelligence Project Artificial Intelligence DrupalAI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057

Risk 32
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Artificial Intelligence Project Artificial Intelligence DrupalAI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056

Risk 29
Severity
4.2
First published (updated )

Artificial Intelligence Project Artificial Intelligence DrupalAI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055

Risk 23
Severity
3.3
First published (updated )

Drupal Drupal AI (Artificial Intelligence)AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054

Risk 38
Severity
6.1
First published (updated )

Drupal Advanced Content Feedback (admin_feedback)Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052

Risk 17
Severity
3.1
First published (updated )

Drupal Advanced Content Feedback (aka admin_feedback)Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Commerce CoreCommerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041

Risk 34
Severity
5.4
First published (updated )

Drupal Drupal 11.4End of life details

EOL
Jul 7, 2027
Support Ends
Jan 1, 2027
First published (updated )

Drupal DrupalThe Media module comes with support for oEmbed. The oEmbed specification contains two discovery mech…

Risk 42
Severity
9
First published (updated )

Drupal DrupalDrupal core ships a rebuild.php front controller that can be used to rebuild Drupal (clearing the ca…

Risk 42
Severity
9
First published (updated )

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203