| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Drupal products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-9726 | The Basket module enables e-commerce and checkout functionality for Drupal sites. The module does not sufficiently sanitize user-supplied data before passing it to PHP's unserialize(). An attacker can... | 9.8 | 588 | Neutral | No |
| Yes |
| CVE-2026-9082 | Drupal core includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks. A vulnerability in this API allows an attacker to s... | 9.8 | 819 | Viral | Yes | Yes |
| CVE-2026-8495 | This module enables you to export entity date fields as iCal feeds. The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds. This vulnerability ... | 9.8 | 653 | Neutral | No | Yes |
| CVE-2026-8493 | This module enables you to open content already on the page within a colorbox. The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-8492 | The GTranslate module provides a language switcher widget for Drupal sites. The module’s widget JavaScript did not sufficiently validate that document.currentScript referred to the executing script el... | 2.7 | 84 | Neutral | No | Yes |
| CVE-2026-8491 | Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page The module doesn't sufficiently handle the case where a user is can... | 3.7 | 102 | Neutral | No | Yes |
| CVE-2026-81269 | Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | 5.3 | 188 | Neutral | No | Yes |
| CVE-2026-81168 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1... | 3.7 | 102 | Neutral | No | Yes |
| CVE-2026-81167 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion... | 4.8 | 202 | Neutral | No | Yes |
| CVE-2026-81162 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best ... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-73475 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | 9.1 | 632 | Neutral | No | Yes |
| CVE-2026-73474 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. | 5.3 | 253 | Neutral | No | Yes |
| CVE-2026-6871 | This module enables you to obfuscate email addresses in content. The module doesn't sufficiently sanitize user input via the Twig filter. This vulnerability is mitigated by the fact that it only affec... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-6816 | An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins:... | 3.8 | 195 | Neutral | Yes | No |
| CVE-2026-6367 | Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross sit... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-6366 | Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a v... | 6.6 | 213 | Neutral | No | Yes |
| CVE-2026-6365 | Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a cross-site scripting (XSS) vulnerability. | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-6095 | The IframeConsent element writes HTML attributes without escaping their value. This module has a XSS vulnerability. If an attacker is able to write an <iframe-consent> tag, they may be able to insert ... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-58591 | The Colorbox module integrates with the Colorbox JavaScript library to display content in an overlay above the page. The module doesn't sufficiently protect against injection of malicious JavaScript u... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-58590 | This module enables you to test and run AI-driven workflows interactively through a chat interface. The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow ite... | 5.4 | 185 | Neutral | No | Yes |