Sploitus

CVE-2026-9082

32 known exploits for CVE-2026-9082

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

Affected products
Drupal, Postgresql
Drupal
< 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
88.3% (100th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2026-05-20
Attack patterns
CAPEC-66
Entry point
filter[a][condition][value][<injected-key>] query param
Path
/jsonapi/node/article
CVE-2026-9082 at NVD
Authoritative description, scoring and affected products

32 known exploits for CVE-2026-9082

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2026-9082
2026-08-26 KitPloitKITPLOIT
CVE-2026-9082-Mass_Scanner
2026-08-26 KitPloitKITPLOIT
CVE-2026-9082-PoC
2026-08-26 KitPloitKITPLOIT
drupal-cve-2026-9082-checker
2026-08-26 KitPloitKITPLOIT
CVE-2026-9082
2026-08-26 KitPloitKITPLOIT
cve-2026-9082
2026-08-26 KitPloitKITPLOIT
CVE-2026-9082
2026-08-26 KitPloitKITPLOIT
CVE-2026-9082
2026-08-26 KitPloitKITPLOIT
cve-2026-9082-drupal-postgresql-rce
2026-08-26 KitPloitKITPLOIT
portfolio-drupal-cve-2026-9082
2026-08-25 KitPloitKITPLOIT
CVE-2026-9082
2026-08-24 KitPloitKITPLOIT
CVE-2026-PoCs
2026-08-24 KitPloitKITPLOIT
CVE-2026-9082-Drupal-PoC
2026-08-24 KitPloitKITPLOIT
drupal-jsonapi-sqli-scanner
2026-08-21 KitPloitKITPLOIT
πŸ“„ Drupal Core 11.3.9 Anonymous Blind SQL Injection
2026-08-05 1dayexploitPACKETSTORMPython
Exploit for CVE-2026-63030
2026-07-19 N45HTGITHUB
--POC
2026-07-12 mjh134GITHUB
Exploit for SQL Injection in Drupal
2026-06-29 evidencebasedvulnerabilityGITHUB
πŸ“„ Drupal core 10.5.5 JSON:API PostgreSQL Error-Based SQL Injection
2026-06-11 indoushkaPACKETSTORM
Exploit for SQL Injection in Drupal
2026-06-07 11romainGITHUB
πŸ“„ Drupal core 10.5.5 SQL Injection
2026-06-02 cardosourcePACKETSTORMPython
Drupal Core 10.5.5 - Error-Based SQL Injection
2026-06-01 cardosourceEXPLOITDBPython
Exploit for SQL Injection in Drupal
2026-05-27 strobelpierreGITHUB
Exploit for SQL Injection in Drupal
2026-05-27 thinhapGITHUB
patch-to-exploit
2026-05-26 unknownhadGITHUB
Exploit for CVE-2026-9082
2026-05-22 ridhinvaGITHUB
Exploit for CVE-2026-9082
2026-05-21 lysophavin18GITHUB
Exploit for CVE-2026-9082
2026-05-21 7h30th3r0n3GITHUB
Exploit for CVE-2026-9082
2026-05-21 HORKimhabGITHUB
Exploit for CVE-2026-9082
2026-05-21 ywh-jfellusGITHUB
CVE-2026-9082
2026-05-20 drupalUNKNOWN
Drupal Core PostgreSQL EntityQuery SQL Injection
2026-05-20 Lukas Johannes MoellerMETASPLOITRuby