Known Vulnerabilities for products from Drupal

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Drupal".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-4933 Not Provided 2026-03-26 2026-03-30
CVE-2026-4393 Not Provided 2026-03-26 2026-03-30
CVE-2026-3573 Not Provided 2026-03-26 2026-03-30
CVE-2026-3532 Not Provided 2026-03-26 2026-03-27
CVE-2026-3531 Not Provided 2026-03-26 2026-03-30
CVE-2026-3530 Not Provided 2026-03-26 2026-03-30
CVE-2026-3529 Not Provided 2026-03-26 2026-03-27
CVE-2026-3528 Not Provided 2026-03-26 2026-03-27
CVE-2026-3527 Not Provided 2026-03-26 2026-03-27
CVE-2026-3526 Not Provided 2026-03-26 2026-03-27
CVE-2022-24775 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-21 2022-03-29
CVE-2022-24729 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2022-03-16 2023-11-07
CVE-2022-24728 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.4 - MEDIUM 2022-03-16 2023-11-07
CVE-2021-41184 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of t... 6.1 - MEDIUM 2021-10-26 2023-08-31
CVE-2021-41183 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` opti... 6.1 - MEDIUM 2021-10-26 2023-08-31
CVE-2021-41182 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` optio... 6.1 - MEDIUM 2021-10-26 2023-08-31
CVE-2021-41165 CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML pro... 5.4 - MEDIUM 2021-11-17 2022-10-05
CVE-2021-41164 CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Con... 5.4 - MEDIUM 2021-11-17 2023-11-07
CVE-2021-33829 A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allow... 6.1 - MEDIUM 2021-06-09 2023-11-07
CVE-2020-36193 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic... 7.5 - HIGH 2021-01-18 2023-11-07

Known software with vulnerabilities from Drupal

Type Vendor Product Version
ApplicationDrupalActivity6.x-1.x
ApplicationDrupalAuthenticated User Page Caching7.x-1.0
ApplicationDrupalData6.x-1.0
ApplicationDrupalDrupal-
ApplicationDrupalQuick Tabs6.x-2.0
ApplicationDrupalRealname6.x-1.2
ApplicationDrupalRestful7.x-1.0
ApplicationDrupalSvg Sanitizer7.x-1.0
ApplicationDrupalViews Builk Operations6.x-1.0
ApplicationDrupalViews Dynamic Field6.x-1.0
ApplicationDrupalWeb Links4.7.x