CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “drupal”

125 vulnerabilities found for “drupal”

Page 1 of 7

CVE-2025-48914
HIGH8.6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

drupal / cookies_consent_management
Network
Published Jun 13, 2025
Page 1 of 7
CVE-2025-48915
HIGH8.6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

drupal / cookies_consent_management
Network
Published Jun 13, 2025
CVE-2025-3474
MEDIUM6.5

Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.

drupal / panels
Network
Published Apr 9, 2025
CVE-2025-3131
MEDIUM5.4

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.

drupal / eca\+2
Network
Published Apr 9, 2025
CVE-2025-3130
MEDIUM5.4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.

drupal / obfuscate
Network
Published Apr 2, 2025
CVE-2025-31692
HIGH7.5

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.

drupal / artificial_intelligence
Network
Published Mar 31, 2025
CVE-2025-31693
MEDIUM6.6

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.

drupal / artificial_intelligence
Network
Published Mar 31, 2025
CVE-2024-34481
MEDIUM6.1

drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page.

kontextwork / drupal_wiki
Network
Published Jul 5, 2024
CVE-2022-31160
MEDIUM6.1

jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.

jqueryui / jquery_ui+14
Network
Published Jul 20, 2022
CVE-2022-26493
CRITICAL9.8

Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating existing users and existing roles, including administrative users/roles. This vulnerability is not mitigated by configuring the module to enforce signatures or certificate checks. Xecurify recommends updating miniOrange modules to their most recent versions. This vulnerability is present in paid versions of the miniOrange Drupal SAML SP product affecting Drupal 7, 8, and 9.

drupal / saml_sp_2.0_single_sign_on+1
Network
Published Jun 3, 2022
CVE-2020-13673
MEDIUM6.1

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.

drupal / entity_embed+10
Network
Published Feb 11, 2022
CVE-2020-35191
CRITICAL9.8

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

drupal / drupal_docker_images+2
Network
Published Dec 17, 2020
CVE-2013-4226
MEDIUM6.5

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.

drupal / authenticated_user_page_caching+5
Network
Published Feb 18, 2020
CVE-2011-2715
CRITICAL9.8

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

drupal / data+1
Network
Published Jan 14, 2020
CVE-2011-2714
MEDIUM6.1

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

drupal / data+1
Network
Published Jan 14, 2020
CVE-2019-19826
CRITICAL9.8

The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.

drupal / views_dynamic_field+4
Network
Published Dec 16, 2019
CVE-2011-3373
MEDIUM6.1

Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.

drupal / views_builk_operations
Network
Published Nov 25, 2019
CVE-2012-2079
HIGH8.8

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

drupal / activity
Network
Published Nov 22, 2019
CVE-2012-2078
MEDIUM4.8

Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.

drupal / activity
Network
Published Nov 21, 2019
CVE-2012-1637
MEDIUM4.8

Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.

drupal / quick_tabs+4
Network
Published Nov 21, 2019