Where
-Infinity
0

Drupal DrupalThe Image module allows you to define and configure image fields. The module doesn't sufficiently ch…

Risk 42
Severity
9
First published (updated )

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Improper validation - SA-CORE-2026-009

Risk 34
Severity
5.4
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Risk 17
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal DrupalDrupal core - Moderately critical - Gadget chain - SA-CORE-2026-006

Risk 45
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007

Risk 35
Severity
5.9
First published (updated )

Drupal DrupalDrupal core - Critical - PHP object injection - SA-CORE-2026-005

Risk 45
Severity
5.9
First published (updated )

Drupal Drupal 11.4End of life details

EOL
Jul 7, 2027
Support Ends
Jan 1, 2027
First published (updated )

Drupal DrupalThe Media module comes with support for oEmbed. The oEmbed specification contains two discovery mech…

Risk 42
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal DrupalDrupal core ships a rebuild.php front controller that can be used to rebuild Drupal (clearing the ca…

Risk 42
Severity
9
First published (updated )

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )

Drupal DrupalSQL Injection

Risk 42
Severity
9
First published (updated )

Drupal DrupalSA-CORE-2019-003 added protection for fields that store serialized data to disallow direct writes vi…

Risk 42
Severity
9
First published (updated )

Drupal DrupalDrupal Core SQL Injection Vulnerability

Risk 99
Severity
9.8
EPSS
88.32%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal DrupalSQL Injection

Risk 46
Severity
9
First published (updated )

Drupal Drupal CoreDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003

Risk 38
Severity
6.1
First published (updated )

Drupal DrupalDrupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002

Risk 61
Severity
6.6
First published (updated )

Drupal DrupalDrupal core - Critical - Cross-site scripting - SA-CORE-2026-001

Risk 38
Severity
6.1
First published (updated )

Drupal DrupalDrupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5.…

Risk 42
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Drupal DrupalXSS

Risk 42
Severity
9
First published (updated )

Drupal DrupalSQL Injection

Risk 42
Severity
9
First published (updated )

Drupal Drupal 11.3Out of support

EOL
Dec 16, 2026
Support Ends
Jun 16, 2026
First published (updated )

Drupal Drupal 10.6Out of support

EOL
Dec 16, 2026
Support Ends
Jun 16, 2026
First published (updated )

composer/drupal/coreDrupal core - Moderately critical - Information disclosure - SA-CORE-2025-008

Risk 20
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/drupal/coreDrupal core - Moderately critical - Gadget chain - SA-CORE-2025-006

Risk 45
Severity
5.9
First published (updated )

Drupal DrupalThe core system module handles downloads of private and temporary files. Contrib modules can define …

Risk 42
Severity
9
First published (updated )

Drupal DrupalBy generating and tricking a user into visiting a malicious URL, an attacker can perform site deface…

Risk 42
Severity
9
First published (updated )

Drupal DrupalDrupal core contains a chain of methods that is exploitable when an insecure deserialization vulnera…

Risk 42
Severity
9
First published (updated )

Drupal DrupalDrupal Core has a rarely used feature, provided by an underlying library, which allows certain attri…

Risk 42
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203