Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 012

fstec логотип

BDU:2026-07320

4 месяца назад

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-07318

4 месяца назад

Уязвимость редактора текста CKEditor CMS-системы Drupal, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-mhpg-hpj5-73r2

8 месяцев назад

Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-m6vv-vcj8-w8m7

8 месяцев назад

Drupal core allows Object Injection

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-83v7-c2cf-p9c2

8 месяцев назад

Drupal core allows Forceful Browsing

EPSS: Низкий
github логотип

GHSA-h89p-5896-f4q8

8 месяцев назад

Drupal core allows Content Spoofing

EPSS: Низкий
nvd логотип

CVE-2025-13083

8 месяцев назад

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-13082

8 месяцев назад

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-13081

8 месяцев назад

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2025-13080

8 месяцев назад

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2026-07320

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07318

Уязвимость редактора текста CKEditor CMS-системы Drupal, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-mhpg-hpj5-73r2

Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels

CVSS3: 3.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-m6vv-vcj8-w8m7

Drupal core allows Object Injection

CVSS3: 5.9
0%
Низкий
8 месяцев назад
github логотип
GHSA-83v7-c2cf-p9c2

Drupal core allows Forceful Browsing

0%
Низкий
8 месяцев назад
github логотип
GHSA-h89p-5896-f4q8

Drupal core allows Content Spoofing

0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-13083

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.

CVSS3: 3.7
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-13082

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-13081

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.9
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-13080

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.

CVSS3: 5.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу


Поделиться