Drupal Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Drupal products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

5

Beyond CISA KEV

0

Sensor Observed

1

Virtual Patch Available

1

Drupal KEVs Added by Year

Loading...

5 Drupal KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-9082

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Confirmed In CISA 01 Jun 2026
CVE-2018-7600

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an...

Confirmed In CISA 03 Nov 2021
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension...

Confirmed In CISA 18 Jan 2022
CVE-2019-6340

Drupal core - Highly critical - Remote Code Execution

Confirmed In CISA 25 Mar 2022
CVE-2018-7602

Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

Confirmed In CISA 13 Apr 2022

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 1
  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology