CVE-2026-55808
- EPSS 0.16%
- Veröffentlicht 10.07.2026 21:46:43
- Zuletzt bearbeitet 16.07.2026 15:02:57
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 1...
CVE-2026-55807
- EPSS 0.14%
- Veröffentlicht 10.07.2026 21:46:40
- Zuletzt bearbeitet 16.07.2026 14:58:17
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0....
CVE-2026-55804
- EPSS 0.22%
- Veröffentlicht 10.07.2026 21:46:39
- Zuletzt bearbeitet 16.07.2026 15:11:21
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14...
CVE-2026-55806
- EPSS 0.21%
- Veröffentlicht 10.07.2026 21:46:39
- Zuletzt bearbeitet 16.07.2026 15:26:23
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, f...
CVE-2026-55803
- EPSS 0.22%
- Veröffentlicht 10.07.2026 21:46:38
- Zuletzt bearbeitet 16.07.2026 15:09:30
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14...
CVE-2026-9082
- EPSS 88.32%
- Veröffentlicht 20.05.2026 18:20:52
- Zuletzt bearbeitet 23.07.2026 16:10:00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before ...
CVE-2026-6367
- EPSS 0.2%
- Veröffentlicht 19.05.2026 22:28:07
- Zuletzt bearbeitet 24.07.2026 08:10:00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.
CVE-2026-6366
- EPSS 0.4%
- Veröffentlicht 19.05.2026 22:27:46
- Zuletzt bearbeitet 24.07.2026 08:10:00
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2....
CVE-2026-6365
- EPSS 0.24%
- Veröffentlicht 19.05.2026 22:27:21
- Zuletzt bearbeitet 24.07.2026 08:10:00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11....
CVE-2026-0749
- EPSS 0.2%
- Veröffentlicht 28.01.2026 18:56:05
- Zuletzt bearbeitet 09.03.2026 14:39:22
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22.