drupal/core vulnerabilities

Licenses: GPL-2.0

Direct Vulnerabilities

Known vulnerabilities in the drupal/core package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
User Interface (UI) Misrepresentation of Critical Information

>=8.0.0, <10.4.9>=10.5.0, <10.5.6>=11.0.0, <11.1.9>=11.2.0, <11.2.8
  • L
Use of Web Browser Cache Containing Sensitive Information

>=8.0.0, <10.4.9>=10.5.0, <10.5.6>=11.0.0, <11.1.9>=11.2.0, <11.2.8
  • H
Deserialization of Untrusted Data

>=8.0.0, <10.4.9>=10.5.0, <10.5.6>=11.0.0, <11.1.9>=11.2.0, <11.2.8
  • M
Improper Check for Unusual or Exceptional Conditions

>=8.0.0, <10.4.9>=10.5.0, <10.5.6>=11.0.0, <11.1.9>=11.2.0, <11.2.8
  • M
Incorrect Authorization

<10.3.13>=10.4.0, <10.4.3>=11.0.0, <11.0.12>=11.1.0, <11.1.3
  • M
Cross-site Scripting (XSS)

<10.3.14>=10.4.0, <10.4.5>=11.0.0, <11.0.13>=11.1.0, <11.1.5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<10.3.13>=10.4.0, <10.4.3>=11.0.0, <11.0.12>=11.1.0, <11.1.3
  • M
Cross-site Scripting (XSS)

<10.3.13>=10.4.0, <10.4.3>=11.0.0, <11.0.12>=11.1.0, <11.1.3
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

>=8.8.0, <10.2.11>=10.3.0, <10.3.9
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8
  • H
Improper Handling of Case Sensitivity

>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8
  • M
Cross-site Scripting (XSS)

>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8
  • H
Infinite loop

>=10.1.0, <10.1.8>=10.2.0, <10.2.2
  • H
Detection of Error Condition Without Action

>=10.0.0, <10.2.10
  • M
Information Exposure

>=8.0.0, <10.2.9>=10.3.0, <10.3.6>=11.0.0, <11.0.5
  • H
Denial of Service (DoS)

>=10.1.0, <10.1.8>=10.2.0, <10.2.2
  • M
Cross-site Scripting (XSS)

<8.8.10>=8.9.0, <8.9.6>=9.0.0, <9.0.6
  • M
URL Redirection to Untrusted Site ('Open Redirect')

<8.2.3
  • H
Improper Handling of Structural Elements Leading to Denial of Service (DoS)

<10.0.0
  • M
Information Exposure

>=8.7.0, <9.5.11>=10.0.0, <10.0.11>=10.1.0, <10.1.4
  • M
Access Control Bypass

>=7.0.0, <7.96>=9.4, <9.4.14>=9.5, <9.5.8>=10.0, <10.0.8
  • M
Cross-site Scripting (XSS)

>=8.0.0, <9.3.19>=9.4.0, <9.4.3
  • M
Access Restriction Bypass

>=8.0.0, <9.3.19>=9.4.0, <9.4.3
  • H
Arbitrary Code Execution

<9.3.19>=9.4.0, <9.4.3
  • M
Information Exposure

<9.3.19>=9.4.0, <9.4.3
  • M
Access Control Bypass

>=9.3.0, <9.3.12
  • H
Improper Input Validation

>=8.0.0, <9.2.18>=9.3.0, <9.3.12
  • M
Improper Input Validation

<9.2.13>=9.3.0, <9.3.6
  • M
Access Restriction Bypass

<9.2.13>=9.3.0, <9.3.6
  • M
Information Exposure

<8.9.19>=9.1.0, <9.1.13>=9.2.0, <9.2.6
  • M
Improper Access Control

<8.9.19>=9.0.0, <9.1.3>=9.2.0, <9.2.6
  • M
Access Restriction Bypass

<8.9.19>=9.0.0, <9.1.13>=9.2.0, <9.2.6
  • M
Cross-site Request Forgery (CSRF)

<8.9.19>=9.0.0, <9.1.13>=9.2.0, <9.2.6
  • M
Cross-site Scripting (XSS)

<7.80>=8.0.0, <8.9.14>=9.0.0, <9.0.12>=9.1.0, <9.1.7
  • H
Arbitrary Code Execution

<8.8.12>=8.9.0, <8.9.10>=9.0.0, <9.0.9
  • H
Remote Code Execution (RCE)

>=7.0.0, <7.74>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.8.0>=8.8.0, <8.8.11>=8.9.0, <8.9.9>=9.0.0, <9.0.8
  • H
Cross-site Request Forgery (CSRF)

>=7.0.0, <7.72>=8.0.0, <8.8.8>=8.9.0, <8.9.1>=9.0.0, <9.0.1
  • M
Remote Code Execution (RCE)

>=8.0.0, <8.8.8>=8.9.0, <8.9.1>=9.0.0, <9.0.1
  • M
Access Restriction Bypass

>=8.0.0, <8.8.8>=8.9.0, <8.9.1>=9.0.0, <9.0.1
  • M
Open Redirect

>=7.0.0, <7.70
  • M
Cross-site Scripting (XSS)

>=7.0.0, <7.70>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.7.14>=8.8.0, <8.8.6
  • M
Denial of Service (DoS)

<8.7.11>=8.8.0, <8.8.1
  • M
Access Restriction Bypass

<8.7.11>=8.8.0, <8.8.1
  • M
Arbitrary File Upload

<8.7.11>=8.8.0, <8.8.1
  • C
Improper Access Control

>=8.7.4, <8.7.5
  • M
Cross-site Scripting (XSS)

<8.5.15>=8.6.0, <8.6.15
  • M
Arbitrary Code Execution

<8.5.15>=8.6.0, <8.6.15
  • M
Access Control Bypass

<8.5.15>=8.6.0, <8.6.16
  • M
Cross-site Scripting (XSS)

>=7.0, <7.65>=8.5, <8.5.14>=8.6, <8.6.13
  • M
Cross-site Scripting (XSS)

>=7.0, <7.65>=8.0.0, <8.5.14>=8.6.0, <8.6.13
  • H
Remote Code Execution (RCE)

<8.5.11>=8.6.0, <8.6.10
  • H
Arbitrary Code Execution

>=7.0.0, <7.6.2>=8.5.0, <8.5.9>=8.6.0, <8.6.6
  • C
Remote Code Execution (RCE)

>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2
  • C
Remote Code Execution (RCE)

>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2
  • H
Open Redirect

>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2
  • C
Access Restriction Bypass

>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2
  • H
Open Redirect

>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2
  • H
Open Redirect

>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2
  • M
Cross-site Scripting (XSS)

>=8.0.0, <8.4.7>=8.5.0, <8.5.2
  • C
Arbitrary Code Execution

<7.59>=8.0, <8.4.8>=8.5.0, <8.5.3
  • M
Cross-site Scripting (XSS)

<8.4.7>=8.5.0, <8.5.2
  • C
Arbitrary Code Execution

<7.58>=8.0, <8.3.9>=8.4.0, <8.4.6>=8.5.0, <8.5.1
  • M
Cross-site Scripting (XSS)

>=7.0, <7.57>=8.0, <8.4.5
  • M
Cross-site Scripting (XSS)

>=7.0.0, <7.57>=8.0.0, <8.4.0
  • M
Access Restriction Bypass

>=8.0, <8.4.5
  • M
Link Injection

>=7.0, <7.57
  • M
Access Restriction Bypass

>=7.0, <7.57
  • H
Information Exposure

>=8.4.0, <8.4.5
  • H
Access Restriction Bypass

>=8.4, <8.4.5
  • M
Access Restriction Bypass

>=8.0, <8.3.7
  • M
Authentication Bypass

>=8.0, <8.3.7
  • M
Access Restriction Bypass

>=8.0, <8.3.7
  • M
Arbitrary File Upload

>=8, <8.3.4
  • C
Deserialization of Untrusted Data

>=8, <8.3.4
  • M
Information Exposure

>=7, <7.56>=8, <8.3.4
  • H
Access Restriction Bypass

>=8.3, <8.3.1<8.2.8
  • H
Cross-site Request Forgery (CSRF)

>=8.0, <8.2.7
  • H
Access Restriction Bypass

>=8.0, <8.2.7
  • H
Arbitrary Code Execution

>=8.0, <8.2.7
  • M
Information Exposure

>=8, <8.2.3
  • M
Denial of Service (DoS)

>=8, <8.2.3
  • H
Cache Poisoning

>=8, <8.2.3
  • M
Cross-site Scripting (XSS)

>=8, <8.1.10
  • M
Access Restriction Bypass

>=8, <8.1.10
  • M
Access Restriction Bypass

>=8, <8.1.10
  • H
HTTP Header Injection

>=8, <8.1.7
  • M
Information Exposure

>=8, <8.1.3
  • H
Privilege Escalation

>=7, <7.44
  • H
Brute Force

>=6, <6.38>=7, <7.43
  • H
Deserialization of Untrusted Data

>=6, <6.38
  • H
Denial of Service (DoS)

>=7, <7.43>=8.0, <8.0.4
  • H
Access Restriction Bypass

>=6, <6.38
  • H
Open Redirect

>=6, <6.38
  • M
Information Exposure

>=7, <7.43>=8, <8.0.4
  • H
Privilege Escalation

>=6, <6.38>=7, <7.43
  • M
Reflected File Download

>=6, <6.38>=7, <7.43
  • M
HTTP Header Injection

>=6, <6.38
  • H
Open Redirect

>=6, <6.38>=7, <7.43>=8.0, <8.0.4