Skip to main content

Daily materialized evidence profile

Vendor drupal

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
866
CVEs with mentions
72
Total mentions
234
CVEs with KEV
8
CVEs with PoC
1

Attack vector counts

Network
859
Adjacent network
0
Local
7
Physical
0

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2026-9082

Published May 20, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: fro…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
78.8
KEV listedPublic PoC observed

CVE-2018-7600

Published Mar 29, 2018

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystem…

CVSS 9.8 · Critical
evidence mentions
56
Buzz score
72.5
KEV listed

CVE-2018-7602

Published Jul 19, 2018

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal sit…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
70.4
KEV listed

CVE-2019-6340

Published Feb 21, 2019

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in…

CVSS 8.1 · High
evidence mentions
13
Buzz score
64.4
KEV listed

CVE-2020-13671

Published Nov 20, 2020

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type…

CVSS 8.8 · High
evidence mentions
8
Buzz score
60.0
KEV listed