21 Total CVEs
10 AI Analyzed
1 CISA KEV
10 Critical
All Vendors
Showing 1-21 of 21 CVEs
CVE-2026-9726
9.8
Drupal Drupal AlternativeCommerce (Basket)

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obje...

2026-07-16
CVE-2026-9082
KEV Analyzed
9.5
Drupal Core

Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.

2026-05-23
CVE-2026-55810
Analyzed
8.1
Drupal Plotly.js Graphing

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. Thi...

2026-07-15
CVE-2026-15089
Analyzed
9.1
Drupal Commerce guest registration

A critical security vulnerability exists in the Drupal Commerce guest registration module, which is now unmaintained and obsolete.

2026-07-15
CVE-2026-15081
Analyzed
9.8
Drupal Location Selector

A critical SQL injection vulnerability in the Drupal Location Selector module allows unauthenticated attackers to execute arbitrary SQL commands via u...

2026-07-15
CVE-2026-15079
Analyzed
9.8
Drupal Login Disable

The Drupal Login Disable module fails to properly restrict excessive authentication attempts, creating a vulnerability that facilitates brute force at...

2026-07-15
CVE-2026-13244
8.1
Drupal Tealium iQ Tag Management

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injecti...

2026-07-16
CVE-2026-13233
Analyzed
9.1
Drupal OpenAI Provider

A Server-Side Request Forgery (SSRF) vulnerability in the Drupal OpenAI Provider module allows remote attackers to force the server to make unauthoriz...

2026-07-15
CVE-2026-12535
Analyzed
9.8
Drupal Formatter Field

The Drupal Formatter Field module contains an object injection vulnerability due to improper control of dynamically determined object attributes.

2026-07-15
CVE-2026-11913
Analyzed
9.8
Drupal Mother May I

A critical vulnerability in the Drupal Mother May I module allows unauthenticated attackers to execute arbitrary code or perform unauthorized actions...

2026-07-16
CVE-2026-10768
Analyzed
9.8
Drupal LocalGov Workflows

A missing authorization vulnerability in the Drupal LocalGov Workflows module allows unauthorized users to access restricted resources via forceful br...

2026-07-15
CVE-2025-9954
7.5
Drupal Multiple Products

Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing

2025-10-30
CVE-2025-8995
Analyzed
9.8
Drupal Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects A...

2025-08-15
CVE-2025-8361
7.6
Drupal Multiple Products

Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing

2025-08-15
CVE-2025-8092
7.6
Drupal Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-S...

2025-08-15
CVE-2025-14840
7.5
Drupal Multiple Products

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing

2026-01-30
CVE-2025-14472
8.1
Drupal Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery

2026-01-30
CVE-2025-13986
7.5
Drupal Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass

2026-01-30
CVE-2025-13982
8.1
Drupal Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery

2026-01-30
CVE-2025-12466
7.5
Drupal Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass

2025-10-30
CVE-2025-12082
7.5
Drupal Multiple Products

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing

2025-10-30