drupal
10 known vulnerabilities affecting drupal products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2018-7602 | Act now | 99.2% | 9.8 | ● | A remote code execution vulnerability exists within multiple subsystems of Drupa… |
| CVE-2026-9082 | Act now | 90.0% | 9.8 | ● | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti… |
| CVE-2021-41184 | Medium | 40.8% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2021-41182 | Medium | 39.4% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2021-41164 | Medium | 1.3% | 8.2 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerab… | |
| CVE-2021-41183 | Low | 8.5% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2020-9281 | Low | 4.3% | 6.1 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEdit… | |
| CVE-2026-6366 | Low | 0.4% | 6.6 | Improperly Controlled Modification of Dynamically-Determined Object Attributes v… | |
| CVE-2026-6365 | Low | 0.2% | 6.1 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti… | |
| CVE-2026-6367 | Low | 0.2% | 6.1 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti… |