Where
AND
-Infinity
0

Drupal Clean RESTfulClean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078

Risk 45
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Improper validation - SA-CORE-2026-009

Risk 34
Severity
5.4
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Gadget chain - SA-CORE-2026-006

Risk 45
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007

Risk 35
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Critical - PHP object injection - SA-CORE-2026-005

Risk 45
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Ray Enterprise TranslationRay Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071

Risk 22
Severity
4.3
First published (updated )

Drupal ColorboxColorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069

Risk 34
Severity
5.4
First published (updated )

Drupal FlowDropFlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068

Risk 34
Severity
5.4
First published (updated )

Drupal FlowDropFlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067

Risk 34
Severity
5.4
First published (updated )

Drupal Canvas Project Drupal Canvas DrupalDrupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Canvas Project Drupal Canvas DrupalDrupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066

Risk 38
Severity
6.1
First published (updated )

Drupal ParagraphsParagraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061

Risk 40
Severity
6.5
First published (updated )

Drupal ParagraphsParagraphs - Less critical - Access bypass - SA-CONTRIB-2026-060

Risk 40
Severity
6.5
First published (updated )

Artificial Intelligence Project Artificial Intelligence DrupalAI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057

Risk 32
Severity
4.8
First published (updated )

Artificial Intelligence Project Artificial Intelligence DrupalAI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056

Risk 29
Severity
4.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Drupal AI (Artificial Intelligence)AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054

Risk 38
Severity
6.1
First published (updated )

Drupal Advanced Content Feedback (aka admin_feedback)Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051

Risk 38
Severity
6.1
First published (updated )

Drupal Commerce CoreCommerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041

Risk 34
Severity
5.4
First published (updated )

Drupal TFA Basic PluginsTFA Basic Plugins - Access Bypass

Risk 31
Severity
5.1
First published (updated )

Drupal Term Reference TreeStored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)

Risk 34
Severity
5.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Drupal CoreDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003

Risk 38
Severity
6.1
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002

Risk 61
Severity
6.6
First published (updated )

Drupal DrupalDrupal core - Critical - Cross-site scripting - SA-CORE-2026-001

Risk 38
Severity
6.1
First published (updated )

Drupal File (Field) PathsInformation disclosure via file URI overwrite in File (Field) Paths

Risk 33
Severity
6.9
First published (updated )

Drupal OpenID Connect / OAuth clientOpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal Calculation FieldsCalculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023

Risk 27
Severity
6.1
EPSS
0.03%
First published (updated )

Drupal SAML SSO - Service ProviderSAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018

Risk 38
Severity
6.1
First published (updated )

Drupal Drupal CanvasDrupal Canvas - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-017

Risk 26
Severity
5
First published (updated )

Jtenman Central Authentication System Server DrupalCentral Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007

Risk 29
Severity
4.2
First published (updated )

Bordeaux-metropole At Internet Piano Analytics DrupalAT Internet Piano Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-004

Risk 29
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203