Known Vulnerabilities for Drupal by Vendor
Listed below are 10 of the newest known vulnerabilities associated with "Drupal" by "Vendor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-4933 | Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpu... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-4393 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue affec... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-3573 | Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI ... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-3532 | Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.This ... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-3531 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authent... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-3530 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.T... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-3529 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-3528 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fiel... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-3527 | Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Configured ... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-3526 | Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File... | Not Provided | 2026-03-26 | 2026-03-27 |