Drupal Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Drupal products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
5
Beyond CISA KEV
0
Sensor Observed
1
Virtual Patch Available
1
Drupal KEVs Added by Year
5 Drupal KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-9082
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 |
Drupal core | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an... |
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-13671
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension... |
Drupal Core | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2019-6340
Drupal core - Highly critical - Remote Code Execution |
Drupal Core | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004 |
core | Confirmed | In CISA | 13 Apr 2022 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 1
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology