108 exploited vulnerabilities in Drupal
- Vendors
- Drupal, Bitnami, Canonical, Postgresql Global Development Group, Unknown, Ampache
- With known exploits
- 108
- Affected Drupal versions
- < 10.5.9, 10.6.7, 11.2.11, 11.3.7, 7.59, 8.4.8, 8.5.3, 7.57, 8.3.9, 8.4.6, 8.5.1, 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10, 8.3.4, 9.3.19, 9.4.3, 6.0, 6.1, 6.2, 6.3, 6.4, 6.5, 6.6, 6.7, 6.8, 6.9, 6.10, 6.11, 6.12, 6.13, 6.14, 6.15, 6.16, 6.17, 6.18, 6.19, 6.20, 6.21, 6.22, 6.23, 6.24, 6.25, 6.26, 6.27, 6.28, 6.29, 6.30, 6.31, 6.32, 6.33, 6.34, 6.35, 6.36, 6.37, 7.0, 7.1, 8.5.11, 8.6.10, 8.4.5, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8, 7.9, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15, 7.16, 7.17, 7.18, 7.19, 7.20, 7.21, 7.22, 7.23, 7.24, 7.25, 7.26, 7.27, 7.28, 7.29, 7.30, 7.31, 7.32, 7.33, 7.34, 7.35, 7.36, 7.37, 7.38, 7.40, 7.91, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.3.0, 4.0, 4.0.0, 4.1.0, 4.2.0_rc, 4.4, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.5, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, 4.5.6, 4.5.7, 4.5.8, 4.6, 4.6.0, 4.6.1, 4.6.2, 4.6.3, 4.6.4, 4.6.5, 4.6.6, 4.6.7, 4.6.8, 4.6.9, 4.6.10, 4.6.11, 4.7, 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4, 4.7.5, 5.2
- Affected Drupal Drupal Docker Images versions
- β€ 8.5.10-fpm-alpine, 8.3.0-fpm-alpine
- Affected Verifone Commerce Paybox versions
- β€ 7.x-1.5
- Affected Debian Debian Linux versions
- = 7.0, 8.0
- Affected Php Xml Rpc versions
- β€ 1.3.0
- Affected Matthiasmullie Minify Js versions
- < 3.0.3
- Affected Mclewin Wishlist versions
- = 6.x-2.1, 6.x-2.2, 6.x-2.4, 7.x-2.5, 7.x-2.x
Vulnerabilities with exploits
Highest CVSS first β 12 of these already have exploit code on Sploitus
CVE-2026-6366
CVE-2025-41240
CVE-2020-35191
CVE-2019-6339
CVE-2018-7602 14 exploits
CVE-2018-7600 50 exploits
CVE-2026-9082 15 exploits
CVE-2017-6925
CVE-2017-6920 7 exploits
Exploit for Improper Input Validation in Joomla Joomla\!Exploit for Improper Input Validation in Joomla Joomla\!
CVE-2022-25277
CVE-2016-6211
CVE-2026-0750
CVE-2016-3168
CVE-2019-6340 23 exploits
Exploit for Deserialization of Untrusted Data in DrupalExploit for Deserialization of Untrusted Data in Drupal
CVE-2017-6930
CVE-2017-6926 1 exploit
CVE-2017-6381
CVE-2016-3171
CVE-2016-3169
CVE-2016-3162
CVE-2025-31674
CVE-2024-22362
CVE-2022-25273
CVE-2022-25275
CVE-2017-6919 1 exploit
CVE-2017-6379
CVE-2017-6377
CVE-2016-9450
CVE-2016-3165
CVE-2016-3163
CVE-2014-3704 23 exploits
CATSploit - An Automated Penetration Testing Tool Using Cyber Attack Techniques ScoringExploit for SQL Injection in Drupal
CVE-2005-1921 8 exploits
CVE-2017-6924
CVE-2016-3167
CVE-2016-3164
CVE-2024-13304
CVE-2012-2069
CVE-2007-6752 2 exploits
CVE-2007-5416 1 exploit
CVE-2025-3733
CVE-2023-31250
CVE-2022-25278
CVE-2022-25270
CVE-2017-6923
CVE-2017-6922
CVE-2017-6931
CVE-2016-9452
CVE-2026-6365
CVE-2024-45440 4 exploits
Exploit for Generation of Error Message Containing Sensitive Information in Drupalπ Drupal 11.x-dev Information Disclosure
CVE-2026-6367