Browse Security Advisories
Security Advisories for drupal/drupal Clear Filters
High
9 months ago
Drupal core contains a potential PHP Object Injection vulnerability
packagist
drupal/drupal, drupal/core-recommended, drupal/core
Low
9 months ago
Drupal core contains a potential PHP Object Injection vulnerability
packagist
drupal/drupal, drupal/core-recommended, drupal/core
High
9 months ago
Drupal core contains a potential PHP Object Injection vulnerability
packagist
drupal/drupal, drupal/core-recommended, drupal/core
Moderate
9 months ago
Drupal core Access bypass
packagist
drupal/drupal, drupal/core-recommended, drupal/core
Moderate
9 months ago
Drupal Core Cross-Site Scripting (XSS)
packagist
drupal/drupal, drupal/core-recommended, drupal/core
Moderate
about 1 year ago
Drupal Full Path Disclosure
packagist
drupal/core, drupal/core-recommended, drupal/drupal
Moderate
over 1 year ago
Drupal Cross-Site Scripting (XSS) affecting CKEditor Third-party library
packagist
drupal/drupal
Moderate
over 1 year ago
Drupal core uses a vulnerable Third-party library CKEditor
packagist
drupal/drupal
High
over 1 year ago
Drupal core Multiple vulnerabilities due to the use of the third-party library Archive_Tar
packagist
drupal/drupal
Critical
over 1 year ago
Drupal Core Insufficient Contextual Links validation leads to Remote Code Execution
packagist
drupal/drupal
Moderate
over 1 year ago
Drupal Malicious file upload with filenames stating with dot
packagist
drupal/drupal
Moderate
over 1 year ago
Drupal External URL injection through URL aliases leading to Open Redirect
packagist
drupal/drupal
Critical
over 1 year ago
Drupal Core Remote Code Execution Vulnerability
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Core Cross-Site Request Forgery (CSRF) vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Core Access bypass vulnerability
packagist
drupal/drupal, drupal/core
Critical
over 3 years ago
Drupal Core Access bypass vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Core Cross-site scripting vulnerability
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Core Arbitrary PHP code execution vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Core Open Redirect vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Cross Site Scripting (XSS) vulnerability
packagist
drupal/drupal, drupal/core
Low
over 3 years ago
Drupal cross-site scripting vulnerability via actions feature and trigger module
packagist
drupal/drupal
High
over 3 years ago
Drupal has open redirect vulnerability in the Overlay module
packagist
drupal/drupal
Moderate
over 3 years ago
Drupal CRLF injection vulnerability in the drupal_set_header function
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Form API ignores access restrictions on submit buttons
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal saving user accounts can sometimes grant the user all roles
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Reflected file download vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal sensitive information disclosure
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Brute force amplification attacks via XML-RPC
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Open redirect vulnerability in the drupal_goto function
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal File upload access bypass and denial of service
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Users without "Administer comments" can set comment visibility on nodes they can edit
packagist
drupal/core, drupal/drupal
Moderate
over 3 years ago
Drupal Cross-site scripting (XSS) vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Unprivileged access to config export
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Views can allow unauthorized users to see Statistics information
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Saving user accounts can sometimes grant the user all roles
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal Denial of service via transliterate mechanism
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Incorrect cache context on password reset page
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal sensitive information disclosure
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal cross site scripting vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal external link injection vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal cross-site scripting vulnerability
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Comment reply form allows access to restricted content
packagist
drupal/drupal, drupal/core
Critical
over 3 years ago
Drupal PECL YAML parser unsafe object handling
packagist
drupal/drupal, drupal/core
Critical
over 3 years ago
Drupal Core Remote Code Execution Vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)
packagist, npm
drupal/drupal, ckeditor-dev, drupal/core
High
over 3 years ago
Drupal access control bypass vulnerability
packagist
drupal/drupal, drupal/core
Critical
over 3 years ago
Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal editor module incorrectly checks access to inline private files
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal REST API can bypass comment approval
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal core access bypass vulnerability
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal file REST resource does not properly validate
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Drupal Core Remote Code Execution Vulnerability
packagist
drupal/drupal, drupal/core
High
over 3 years ago
HTTP Proxy header vulnerability
packagist
typo3/cms, drupal/drupal, bugsnag/bugsnag-laravel, amphp/artax, padraic/humbug_get_contents, drupal/core, guzzlehttp/guzzle
Moderate
over 3 years ago
Drupal core Cross-site Scripting (XSS) vulnerability
packagist
drupal/drupal, drupal/core
High
over 3 years ago
Exposure of Resource to Wrong Sphere in Drupal Core
packagist
drupal/drupal, drupal/core
Moderate
over 3 years ago
Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor
packagist
drupal/drupal, drupal/core
Critical
over 3 years ago
Arbitrary PHP code execution in Drupal
packagist
drupal/core, drupal/drupal
High
almost 4 years ago
Drupal core Unrestricted Upload of File with Dangerous Type
packagist
drupal/drupal, drupal/core
Critical
almost 4 years ago
Directory Traversal in typo3/phar-stream-wrapper
packagist
drupal/drupal, drupal/core, typo3/phar-stream-wrapper
Moderate
about 4 years ago
ckeditor4 vulnerable to cross-site scripting
packagist, npm
drupal/drupal, drupal/core, ckeditor4
High
almost 6 years ago
Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data
packagist
drupal/drupal
Moderate
almost 6 years ago
Symfony Cross-site Scripting (XSS) vulnerability
packagist
drupal/drupal, drupal/core, symfony/symfony, symfony/framework-bundle
Filter by Severity
Filter by Ecosystem
maven
6,869
packagist
5,422
pypi
4,942
npm
4,297
go
2,920
nuget
1,880
cargo
1,086
rubygems
927
actions
37
hex
37
swift
36
pub
10
Filter by Package
tensorflow
433
tensorflow-gpu
427
tensorflow-cpu
423
moodle/moodle
418
magento/community-edition
302
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
239
typo3/cms
190
com.liferay.portal:release.portal.bom
141
org.apache.tomcat:tomcat
136
com.liferay.portal:release.dxp.bom
125
github.com/mattermost/mattermost/server/v8
124
pimcore/pimcore
120
dolibarr/dolibarr
116
typo3/cms-core
114
Django
108
phpmyadmin/phpmyadmin
107
microweber/microweber
103
drupal/core
103
magento/project-community-edition
102
silverstripe/framework
92
apache-airflow
85
librenms/librenms
83
drupal/drupal
83
thorsten/phpmyfaq
73
Plone
72
com.fasterxml.jackson.core:jackson-databind
69
symfony/symfony
69
github.com/usememos/memos
68
concrete5/concrete5
67
salt
65
ansible
63
apache-superset
61
actionpack
61
shopware/platform
58
org.apache.struts:struts2-core
57
github.com/grafana/grafana
56
craftcms/cms
53
mlflow
53
org.keycloak:keycloak-core
50
github.com/hashicorp/vault
49
org.apache.tomcat.embed:tomcat-embed-core
48
mautic/core
48
nova
48
baserproject/basercms
47
django
46
nokogiri
46
shopware/core
46
github.com/mattermost/mattermost-server/v6
45
github.com/rancher/rancher
45
vyper
44
gradio
44
org.xwiki.platform:xwiki-platform-oldcore
43
rdiffweb
42
org.keycloak:keycloak-services
42
nilsteampassnet/teampass
42
matrix-synapse
42
k8s.io/kubernetes
42
showdoc/showdoc
41
plone
41
org.elasticsearch:elasticsearch
41
mantisbt/mantisbt
41
intelliants/subrion
40
froxlor/froxlor
40
directus
39
picklescan
39
github.com/mattermost/mattermost-server
38
com.thoughtworks.xstream:xstream
37
net.mingsoft:ms-mcms
36
com.jfinal:jfinal
36
snipe/snipe-it
36
moin
35
io.undertow:undertow-core
35
zendframework/zendframework1
34
org.jenkins-ci.plugins:script-security
34
github.com/answerdev/answer
34
parse-server
33
gogs.io/gogs
33
keystone
32
github.com/argoproj/argo-cd/v2
32
opencv-python
31
opencv-contrib-python
31
github.com/hashicorp/nomad
31
shopware/shopware
31
github.com/cilium/cilium
31
github.com/argoproj/argo-cd
31
github.com/docker/docker
31
getgrav/grav
30
github.com/hashicorp/consul
29
rack
29
Pillow
29
next
29
electron
29
contao/core-bundle
29
mediawiki/core
28
org.apache.solr:solr-core
28
pillow
28
prestashop/prestashop
27
centreon/centreon
27
org.opencms:opencms-core
27
openssl-src
26
org.springframework.security:spring-security-core
26
github.com/traefik/traefik/v2
25
vllm
25
org.eclipse.jetty:jetty-server
25
rubygems-update
25
open-webui
25
pocketmine/pocketmine-mp
25
surrealdb
24
magento/core
24
getkirby/cms
24
org.keycloak:keycloak-parent
24
phpoffice/phpexcel
23
org.bouncycastle:bcprov-jdk14
23
org.bouncycastle:bcprov-jdk15on
23
grumpydictator/firefly-iii
23
laravel/framework
23
zendframework/zendframework
23
simplesamlphp/simplesamlphp
23
puppet
23
org.apache.tomcat:tomcat-catalina
23
pyload-ng
23
remdex/livehelperchat
23
Microsoft.AspNetCore.App.Runtime.win-x64
22
DotNetNuke.Core
22
tribalsystems/zenario
22
phpoffice/phpspreadsheet
22
contao/contao
22
@openzeppelin/contracts-upgradeable
22
ckb
22
org.apache.openmeetings:openmeetings-parent
22
activerecord
22
Microsoft.AspNetCore.App.Runtime.win-x86
22
helm.sh/helm/v3
21
github.com/ethereum/go-ethereum
21
@openzeppelin/contracts
21
glance
21
Microsoft.AspNetCore.App.Runtime.win-arm
21
github.com/goharbor/harbor
21
org.apache.nifi:nifi
21
cockpit-hq/cockpit
20
code.gitea.io/gitea
20
aim
20
org.apache.tomcat:tomcat-coyote
20
org.cloudfoundry.identity:cloudfoundry-identity-server
20
wasmtime
20
funadmin/funadmin
20
golang.org/x/net
20
langchain
20
typo3/cms-backend
20
org.xwiki.platform:xwiki-platform-web-templates
20
ethyca-fides
20
Microsoft.AspNetCore.App.Runtime.linux-x64
19
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
19
Microsoft.AspNetCore.App.Runtime.osx-x64
19
github.com/zitadel/zitadel
19
Microsoft.AspNetCore.App.Runtime.linux-arm
19
topthink/framework
19
neutron
19
deno
19
Microsoft.AspNetCore.App.Runtime.linux-arm64
19
Microsoft.AspNetCore.App.Runtime.win-arm64
19
mercurial
18
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
18
genix/cms
18
forkcms/forkcms
18
cobbler
18
com.vaadin:vaadin-bom
18
flowise
18
org.apache.jspwiki:jspwiki-main
18
mindsdb
18
org.apache.inlong:manager-pojo
17
cryptography
17
ezsystems/ezpublish-kernel
17
yetiforce/yetiforce-crm
17
github.com/traefik/traefik/v3
17
calibreweb
17
cakephp/cakephp
17
francoisjacquet/rosariosis
17
opencart/opencart
17
org.springframework:spring-core
17
org.apache.geode:geode-core
17
symfony/security
17
github.com/openfga/openfga
17
notebook
17
OctoPrint
17
openmage/magento-lts
17
org.apache.activemq:activemq-client
16
Microsoft.NetCore.App.Runtime.win-x64
16
transformers
16
rusqlite
16
sequelize
16
Microsoft.NetCore.App.Runtime.win-arm64
16
tinymce
16
org.apache.dubbo:dubbo
16
Microsoft.NetCore.App.Runtime.win-x86
16
org.bouncycastle:bcprov-jdk15
16
Microsoft.NetCore.App.Runtime.win-arm
16
lollms
16
october/system
16
Filter by Repository
https://github.com/drupal/core
8
https://github.com/drupal/drupal
2
https://github.com/symfony/symfony
1
https://github.com/guzzle/guzzle
1
https://github.com/ckeditor/ckeditor-dev
1
https://github.com/github/advisory-database
1
https://github.com/a2u/CVE-2018-7600
1
https://github.com/TYPO3/phar-stream-wrapper
1