Vulnerabilidades em Drupal

398 resultados
Análise Vexday

O Drupal acumula 309 CVEs catalogadas, com 23 classificadas como críticas e 4 confirmadas em exploração ativa pelo catálogo KEV da CISA — uma taxa que é 2,9 vezes acima da média geral do catálogo, o que indica risco operacional concreto e não meramente teórico. A CVE mais perigosa em exploração ativa, CVE-2018-7602, apresenta EPSS de 0,9907, sinalizando altíssima probabilidade de exploração e exigindo atenção imediata em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão recorrente em plataformas de gerenciamento de conteúdo que requer controles rigorosos de sanitização de entrada e saída. As 14 CVEs surgidas nos últimos 90 dias e a existência de 6 vulnerabilidades com PoC pública reforçam a necessidade de ciclos de patching frequentes e monitoramento contínuo para instalações Drupal em produção.

CVE-2020-13668Access bypass in Drupal Core 8/9EPSS 0.7%CVE-2020-13672Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circuEPSS 0.7%CVE-2022-25275HIGHIn some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when gEPSS 0.7%CVE-2020-13688Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in orEPSS 0.7%CVE-2020-13669Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x verEPSS 0.6%CVE-2024-13258CRITICALDrupal REST & JSON API Authentication - Moderately critical - Access bypass - SA-CONTRIB-2024-022EPSS 0.6%CVE-2022-25278MEDIUMUnder certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alterEPSS 0.6%CVE-2025-31674HIGHDrupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003EPSS 0.6%CVE-2022-25273HIGHDrupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validationEPSS 0.6%CVE-2026-11913CRITICALMother May I - Critical - Unsupported - SA-CONTRIB-2026-045EPSS 0.6%CVE-2026-9726CRITICALDrupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038EPSS 0.6%CVE-2026-12535CRITICALFormatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048EPSS 0.6%CVE-2024-13239CRITICALTwo-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003EPSS 0.6%CVE-2024-13265HIGHOpigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029EPSS 0.6%CVE-2024-13267HIGHOpigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031EPSS 0.6%CVE-2025-31676HIGHEmail TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001EPSS 0.6%CVE-2023-31250MEDIUMDrupal core - Moderately critical - Access bypass - SA-CORE-2023-005EPSS 0.5%CVE-2022-25276MEDIUMThe Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of thEPSS 0.5%CVE-2025-8995CRITICALAuthenticator Login - Highly critical - Access bypass - SA-CONTRIB-2025-096EPSS 0.5%CVE-2025-3060MEDIUMFlattern – Multipurpose Bootstrap Business Profile - Critical - Unsupported - SA-CONTRIB-2025-005EPSS 0.5%