drupal/core vulnerabilities

Drupal is an open source content management platform powering millions of websites and applications.

Direct Vulnerabilities

Known vulnerabilities in the drupal/core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Execution

<9.3.19 >=9.4.0, <9.4.3
  • M
Information Exposure

<9.3.19 >=9.4.0, <9.4.3
  • M
Access Control Bypass

>=9.3.0, <9.3.12
  • H
Improper Input Validation

>=9.0.0, <9.2.18 >=9.3.0, <9.3.12
  • M
Improper Input Validation

<9.2.13 >=9.3.0, <9.3.6
  • M
Access Restriction Bypass

<9.2.13 >=9.3.0, <9.3.6
  • M
Information Exposure

<8.9.19 >=9.1.0, <9.1.13 >=9.2.0, <9.2.6
  • M
Improper Access Control

<8.9.19 >=9.0.0, <9.1.3 >=9.2.0, <9.2.6
  • M
Access Restriction Bypass

<8.9.19 >=9.0.0, <9.1.13 >=9.2.0, <9.2.6
  • M
Cross-site Request Forgery (CSRF)

<8.9.19 >=9.0.0, <9.1.13 >=9.2.0, <9.2.6
  • M
Cross-site Scripting (XSS)

<7.80 >=8.0.0, <8.9.14 >=9.0.0, <9.0.12 >=9.1.0, <9.1.7
  • H
Arbitrary Code Execution

<8.8.12 >=8.9.0, <8.9.10 >=9.0.0, <9.0.9
  • H
Remote Code Execution (RCE)

>=7.0.0, <7.74 >=8.0.0, <8.1.0 >=8.1.0, <8.2.0 >=8.2.0, <8.3.0 >=8.3.0, <8.4.0 >=8.4.0, <8.5.0 >=8.5.0, <8.6.0 >=8.6.0, <8.7.0 >=8.7.0, <8.8.0 >=8.8.0, <8.8.11 >=8.9.0, <8.9.9 >=9.0.0, <9.0.8
  • H
Cross-site Request Forgery (CSRF)

>=7.0.0, <7.72 >=8.0.0, <8.8.8 >=8.9.0, <8.9.1 >=9.0.0, <9.0.1
  • M
Remote Code Execution (RCE)

>=8.0.0, <8.8.8 >=8.9.0, <8.9.1 >=9.0.0, <9.0.1
  • M
Access Restriction Bypass

>=8.0.0, <8.8.8 >=8.9.0, <8.9.1 >=9.0.0, <9.0.1
  • M
Open Redirect

>=7.0.0, <7.70
  • M
Cross-site Scripting (XSS)

>=7.0.0, <7.70 >=8.0.0, <8.1.0 >=8.1.0, <8.2.0 >=8.2.0, <8.3.0 >=8.3.0, <8.4.0 >=8.4.0, <8.5.0 >=8.5.0, <8.6.0 >=8.6.0, <8.7.0 >=8.7.0, <8.7.14 >=8.8.0, <8.8.6
  • M
Denial of Service (DoS)

<8.7.11 >=8.8.0, <8.8.1
  • M
Access Restriction Bypass

<8.7.11 >=8.8.0, <8.8.1
  • M
Arbitrary File Upload

<8.7.11 >=8.8.0, <8.8.1
  • C
Improper Access Control

>=8.7.4, <8.7.5
  • M
Arbitrary Code Execution

<8.5.15 >=8.6.0, <8.6.15
  • M
Access Control Bypass

<8.5.15 >=8.6.0, <8.6.16
  • M
Cross-site Scripting (XSS)

<8.5.15 >=8.6.0, <8.6.15
  • M
Cross-site Scripting (XSS)

>=7.0, <7.65 >=8.5, <8.5.14 >=8.6, <8.6.13
  • M
Cross-site Scripting (XSS)

>=7.0, <7.65 >=8.0.0, <8.5.14 >=8.6.0, <8.6.13
  • H
Remote Code Execution (RCE)

<8.5.11 >=8.6.0, <8.6.10
  • H
Arbitrary Code Execution

>=7.0.0, <7.6.2 >=8.5.0, <8.5.9 >=8.6.0, <8.6.6
  • C
Remote Code Execution

>=7.0.0, <7.60 >=8.0.0, <8.5.8 >=8.6.0, <8.6.2
  • C
Remote Code Execution

>=7.0.0, <7.60 >=8.0.0, <8.5.8 >=8.6.0, <8.6.2
  • H
Open Redirect

>=7.0.0, <7.60 >=8.0.0, <8.5.8 >=8.6.0, <8.6.2
  • C
Access Restriction Bypass

>=7.0.0, <7.60 >=8.0.0, <8.5.8 >=8.6.0, <8.6.2
  • H
Open Redirect

>=7.0.0, <7.60 >=8.0.0, <8.5.8 >=8.6.0, <8.6.2
  • H
Open Redirect

>=7.0.0, <7.60 >=8.0.0, <8.5.8 >=8.6.0, <8.6.2
  • M
Cross-site Scripting (XSS)

>=8.0.0, <8.4.7 >=8.5.0, <8.5.2
  • C
Arbitrary Code Execution

<7.59 >=8.0, <8.4.8 >=8.5.0, <8.5.3
  • M
Cross-site Scripting (XSS)

<8.4.7 >=8.5.0, <8.5.2
  • C
Arbitrary Code Execution

<7.58 >=8.0, <8.3.9 >=8.4.0, <8.4.6 >=8.5.0, <8.5.1
  • M
Cross-site Scripting (XSS)

>=7.0, <7.57 >=8.0, <8.4.5
  • M
Cross-site Scripting (XSS)

>=7.0.0, <7.57 >=8.0.0, <8.4.0
  • M
Access Restriction Bypass

>=8.0, <8.4.5
  • M
Link Injection

>=7.0, <7.57
  • M
Access Restriction Bypass

>=7.0, <7.57
  • H
Information Exposure

>=8.4.0, <8.4.5
  • H
Access Restriction Bypass

>=8.4, <8.4.5
  • M
Authentication Bypass

>=8.0, <8.3.7
  • M
Access Restriction Bypass

>=8.0, <8.3.7
  • M
Access Restriction Bypass

>=8.0, <8.3.7
  • M
Arbitrary File Upload

>=8, <8.3.4
  • C
Deserialization of Untrusted Data

>=8, <8.3.4
  • M
Information Exposure

>=7, <7.56 >=8, <8.3.4
  • H
Access Restriction Bypass

>=8.3, <8.3.1 <8.2.8
  • H
Cross-site Request Forgery (CSRF)

>=8.0, <8.2.7
  • H
Arbitrary Code Execution

>=8.0, <8.2.7
  • H
Access Restriction Bypass

>=8.0, <8.2.7
  • M
Denial of Service (DoS)

>=8, <8.2.3
  • M
Information Exposure

>=8, <8.2.3
  • H
Cache Poisoning

>=8, <8.2.3
  • M
Cross-site Scripting (XSS)

>=8, <8.1.10
  • M
Access Restriction Bypass

>=8, <8.1.10
  • M
Access Restriction Bypass

>=8, <8.1.10
  • H
HTTP Header Injection

>=8, <8.1.7
  • M
Information Exposure

>=8, <8.1.3
  • H
Privilege Escalation

>=7, <7.44
  • H
Open Redirect

>=6, <6.38 >=7, <7.43 >=8.0, <8.0.4
  • M
HTTP Header Injection

>=6, <6.38
  • H
Privilege Escalation

>=6, <6.38 >=7, <7.43
  • H
Denial of Service (DoS)

>=7, <7.43 >=8.0, <8.0.4
  • M
Reflected File Download

>=6, <6.38 >=7, <7.43
  • H
Open Redirect

>=6, <6.38
  • M
Information Exposure

>=7, <7.43 >=8, <8.0.4
  • H
Access Restriction Bypass

>=6, <6.38
  • H
Brute Force

>=6, <6.38 >=7, <7.43
  • H
Deserialization of Untrusted Data

>=6, <6.38