| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Drupal products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-9726 | The Basket module enables e-commerce and checkout functionality for Drupal sites. The module does not sufficiently sanitize user-supplied data before passing it to PHP's unserialize(). An attacker can... | 9.8 | 588 | Neutral | No |
| Yes |
| CVE-2026-9082 | Drupal core includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks. A vulnerability in this API allows an attacker to s... | 9.8 | 819 | Viral | Yes | Yes |
| CVE-2026-8495 | This module enables you to export entity date fields as iCal feeds. The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds. This vulnerability ... | 9.8 | 653 | Neutral | No | Yes |
| CVE-2026-8493 | This module enables you to open content already on the page within a colorbox. The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-8492 | The GTranslate module provides a language switcher widget for Drupal sites. The module’s widget JavaScript did not sufficiently validate that document.currentScript referred to the executing script el... | 2.7 | 84 | Neutral | No | Yes |
| CVE-2026-8491 | Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page The module doesn't sufficiently handle the case where a user is can... | 3.7 | 102 | Neutral | No | Yes |
| CVE-2026-6871 | This module enables you to obfuscate email addresses in content. The module doesn't sufficiently sanitize user input via the Twig filter. This vulnerability is mitigated by the fact that it only affec... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-6816 | An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins:... | 3.8 | 195 | Neutral | Yes | No |
| CVE-2026-6367 | Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross sit... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-6366 | Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a v... | 6.6 | 213 | Neutral | No | Yes |
| CVE-2026-6365 | Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a cross-site scripting (XSS) vulnerability. | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-6095 | The IframeConsent element writes HTML attributes without escaping their value. This module has a XSS vulnerability. If an attacker is able to write an <iframe-consent> tag, they may be able to insert ... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-58591 | The Colorbox module integrates with the Colorbox JavaScript library to display content in an overlay above the page. The module doesn't sufficiently protect against injection of malicious JavaScript u... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-58590 | This module enables you to test and run AI-driven workflows interactively through a chat interface. The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow ite... | 5.4 | 185 | Neutral | No | Yes |
| CVE-2026-58589 | This module enables you to test and run AI-driven workflows interactively through a chat interface. The module doesn't sufficiently enforce permissions on certain endpoints. Attackers may be able to t... | 5.4 | 185 | Neutral | No | Yes |
| CVE-2026-58588 | The Canvas module allow you to upload image files via a custom API. The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious user to up... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-58587 | The Canvas AI submodule allows you to upload image files via a custom API to use within the AI web chat. These file uploads are insufficiently validated before being written to Drupal's temporary dire... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-55810 | The Plotly.js Graphing module provides a fully customizable implementation of the open source Plotly.js graphing library. The module stores some data as PHP-serialized strings. In some situations, mal... | 8.1 | 476 | Neutral | No | Yes |
| CVE-2026-55809 | The Flag attendance field module gives you the ability to add attendance by depending on Flag module. flag_attendance_field stores some data as PHP-serialized strings. In some situations, malicious da... | 8.1 | 476 | Neutral | No | Yes |
| CVE-2026-55808 | The JSON:API and REST modules allow you to upload image files to image fields. The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious... | 5.4 | 223 | Neutral | No | Yes |