Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • H
Open Redirect
drupal/drupal>=7.0, <7.24Composer31 Oct 2024
  • H
Arbitrary Code Execution
drupal/drupal<8.8.12>=8.9.0, <8.9.10>=9.0.0, <9.0.9Composer4 Dec 2020
  • M
Access Restriction Bypass
drupal/drupal>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.8.0>=8.8.0, <8.8.10>=8.9.0, <8.9.6>=9.0.0, <9.0.6Composer18 Sept 2020
  • M
Information Disclosure
drupal/drupal>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.8.0>=8.8.0, <8.8.10>=8.9.0, <8.9.6>=9.0.0, <9.0.6Composer18 Sept 2020
  • C
Cross-site Scripting (XSS)
drupal/drupal>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.8.0>=8.8.0, <8.8.10>=8.9.0, <8.9.6>=9.0.0, <9.0.6Composer18 Sept 2020
  • C
Cross-site Scripting (XSS)
drupal/drupal>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.8.0>=8.8.0, <8.8.10>=8.9.0, <8.9.6>=9.0.0, <9.0.6Composer18 Sept 2020
  • M
Cross-site Scripting (XSS)
drupal/drupal>=7.0.0, <7.73>=8.0.0, <8.1.0>=8.1.0, <8.2.0>=8.2.0, <8.3.0>=8.3.0, <8.4.0>=8.4.0, <8.5.0>=8.5.0, <8.6.0>=8.6.0, <8.7.0>=8.7.0, <8.8.0>=8.8.0, <8.8.10>=8.9.0, <8.9.6>=9.0.0, <9.0.6Composer18 Sept 2020
  • M
Access Restriction Bypass
drupal/drupal<8.7.11>=8.8.0, <8.8.1Composer22 Dec 2019
  • M
Denial of Service (DoS)
drupal/drupal<8.7.11>=8.8.0, <8.8.1Composer22 Dec 2019
  • M
Arbitrary File Upload
drupal/drupal<8.7.11>=8.8.0, <8.8.1Composer22 Dec 2019
  • M
Arbitrary Code Execution
drupal/drupal<8.5.15>=8.6.0, <8.6.15Composer24 Apr 2019
  • M
Cross-site Scripting (XSS)
drupal/drupal<8.5.15>=8.6.0, <8.6.15Composer24 Apr 2019
  • M
Access Control Bypass
drupal/drupal<8.5.15>=8.6.0, <8.6.16Composer24 Apr 2019
  • M
Cross-site Scripting (XSS)
drupal/drupal>=7.0, <7.65>=8.0.0, <8.5.14>=8.6.0, <8.6.13Composer21 Mar 2019
  • H
Remote Code Execution (RCE)
drupal/drupal<8.5.11>=8.6.0, <8.6.10Composer22 Feb 2019
  • H
Arbitrary Code Execution
drupal/drupal>=7.0.0, <7.6.2>=8.5.0, <8.5.9>=8.6.0, <8.6.6Composer4 Feb 2019
  • C
Remote Code Execution
drupal/drupal>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2Composer22 Oct 2018
  • C
Remote Code Execution
drupal/drupal>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2Composer22 Oct 2018
  • H
Open Redirect
drupal/drupal>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2Composer22 Oct 2018
  • C
Access Restriction Bypass
drupal/drupal>=7.0.0, <7.60>=8.0.0, <8.5.8>=8.6.0, <8.6.2Composer22 Oct 2018
  • M
Cross-site Scripting (XSS)
drupal/drupal>=8.0.0, <8.4.7>=8.5.0, <8.5.2Composer10 May 2018
  • C
Arbitrary Code Execution
drupal/drupal<7.59.0>=8.0.0, <8.4.8>=8.5.0, <8.5.3Composer10 May 2018
  • C
Arbitrary Code Execution
drupal/drupal>=0.0.0, <7.58>=8.0.0, <8.3.9>=8.4.0, <8.4.6>=8.5.0, <8.5.1Composer2 Apr 2018
  • M
Cross-site Scripting (XSS)
drupal/drupal>=7.0.0, <7.57>=8.0.0, <8.4.5Composer6 Mar 2018
  • M
Cross-site Scripting (XSS)
drupal/drupal>=7.0.0, <7.57>=8.0.0, <8.4.0Composer6 Mar 2018
  • M
Access Restriction Bypass
drupal/drupal>=8.0, <8.4.5Composer6 Mar 2018
  • M
Link Injection
drupal/drupal>=7.0, <7.57Composer6 Mar 2018
  • M
Access Restriction Bypass
drupal/drupal>=7.0, <7.57Composer6 Mar 2018
  • H
Information Exposure
drupal/drupal>=8.4.0, <8.4.5Composer6 Mar 2018
  • H
Access Restriction Bypass
drupal/drupal>=8.4.0, <8.4.5Composer6 Mar 2018