Drupal

Drupal

281 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 10.07.2026 21:46:43
  • Zuletzt bearbeitet 16.07.2026 15:02:57

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 1...

  • EPSS 0.14%
  • Veröffentlicht 10.07.2026 21:46:40
  • Zuletzt bearbeitet 16.07.2026 14:58:17

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0....

  • EPSS 0.22%
  • Veröffentlicht 10.07.2026 21:46:39
  • Zuletzt bearbeitet 16.07.2026 15:11:21

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14...

  • EPSS 0.21%
  • Veröffentlicht 10.07.2026 21:46:39
  • Zuletzt bearbeitet 16.07.2026 15:26:23

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, f...

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 10.07.2026 21:46:38
  • Zuletzt bearbeitet 16.07.2026 15:09:30

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14...

Warnung Medienbericht
  • EPSS 88.32%
  • Veröffentlicht 20.05.2026 18:20:52
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before ...

  • EPSS 0.2%
  • Veröffentlicht 19.05.2026 22:28:07
  • Zuletzt bearbeitet 24.07.2026 08:10:00

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.

  • EPSS 0.4%
  • Veröffentlicht 19.05.2026 22:27:46
  • Zuletzt bearbeitet 24.07.2026 08:10:00

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2....

  • EPSS 0.24%
  • Veröffentlicht 19.05.2026 22:27:21
  • Zuletzt bearbeitet 24.07.2026 08:10:00

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11....

Exploit
  • EPSS 0.2%
  • Veröffentlicht 28.01.2026 18:56:05
  • Zuletzt bearbeitet 09.03.2026 14:39:22

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22.