Skip to content
Threat Feed

Vendor

Drupal

10 briefs RSS
high threat

Critical Access Bypass Vulnerability in Drupal Internationalization Single Sign-On Module

A critical access bypass vulnerability (SA-CONTRIB-2026-081) exists in the Internationalization Single Sign-On module for Drupal, affecting versions prior to 1.8.0, allowing an attacker to bypass authentication mechanisms and potentially gain unauthorized access or elevate privileges within the application.

exploited Internationalization Single Sign-On drupal cms vulnerability access-bypass web-application
1t
low advisory

Drupal OpenAI Provider Module Vulnerable to Server-Side Request Forgery and Local File Read (CVE-2026-13233)

A moderately critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-13233, in the Drupal OpenAI Provider (`ai_provider_openai`) module allows attackers to achieve local file reads or access internal network services by manipulating the upstream AI API response, with a public exploit now available.

OpenAI Provider +1 SSRF file-read Drupal CVE web-application
2r 3t 1c 5i
high advisory

Multiple Vulnerabilities Discovered in Drupal Leading to XSS and Data Confidentiality Breach

Multiple vulnerabilities have been discovered in Drupal, allowing an attacker to achieve indirect remote code injection via Cross-Site Scripting (XSS) and compromise data confidentiality across various versions.

Drupal +2 web-application vulnerability xss data-breach
3t
medium advisory

Drupal Core: Multiple Vulnerabilities Allowing Information Disclosure and XSS

A remote, unauthenticated attacker can exploit multiple vulnerabilities in Drupal Core to achieve information disclosure and Cross-Site Scripting (XSS) attacks, potentially compromising user data or session integrity.

Drupal Core vulnerability web-application xss information-disclosure cve-less
2t
critical threat

Drupal AlternativeCommerce (Basket) Module Vulnerability Allows Code Execution

A critical vulnerability in the Drupal 'AlternativeCommerce' (Basket) module allows a remote, unauthenticated attacker to execute arbitrary program code. This can lead to full compromise of the affected web application.

exploited AlternativeCommerce drupal rce web-vulnerability
2t
critical advisory

Critical SQL Injection Vulnerability in Drupal Location Selector Module (SA-CONTRIB-2026-072)

A critical SQL Injection vulnerability (SA-CONTRIB-2026-072) has been identified in Drupal's Location Selector module, affecting versions prior to 1.3.0, allowing unauthenticated attackers to execute arbitrary SQL commands and potentially leading to unauthorized data access, modification, or deletion.

Location Selector module < 1.3.0 sql-injection web-application drupal
1r 3t
high threat

Drupal Security Advisory AV26-615: Multiple Critical Vulnerabilities

On June 17, 2026, Drupal released critical security advisories (AV26-615) addressing multiple vulnerabilities in Drupal core and several modules including Plotly.js Graphing, Flag attendance field, and Formatter Field, which, if unpatched, could allow remote attackers to compromise affected web servers and sensitive data.

exploited Drupal core +3 web-application drupal vulnerability cccs-advisory
3r 7t
critical threat

Drupal Core PostgreSQL SQL Injection Vulnerability (CVE-2026-9082) Exploit Available

A public exploit is available for CVE-2026-9082, a SQL injection vulnerability in Drupal Core affecting PostgreSQL-backed sites running versions 8.0 through 11.3.9, allowing unauthenticated users to potentially achieve data exfiltration, privilege escalation, and remote code execution.

Drupal Core cve sql injection drupal web application
2r 1t 1c 2i
critical advisory

Drupal Date iCal Module Vulnerability Allows Information Disclosure

A critical information disclosure vulnerability exists in the Drupal Date iCal module versions prior to 4.0.15, potentially allowing unauthorized access to sensitive information.

Date iCal < 4.0.15 drupal information-disclosure vulnerability
2r 1t
high advisory

webonyx/graphql-php Unbounded Recursion Vulnerability

The webonyx/graphql-php library has an unbounded recursion vulnerability in its parser that can lead to a stack overflow, causing a denial of service by terminating the PHP process with a SIGSEGV.

graphql-php +4 graphql denial-of-service recursion php
2r 1t