FAIL › dossier
Drupal
VENDOR· dossier confidence 33%
Drupal, a widely used open-source CMS, has a history of critical security vulnerabilities, including remote code execution flaws exploited in ransomware attacks. Regular updates and diligent security practices are essential for mitigating risk.
PROFILE
CategoryContent Management SystemWhat they doDrupal is an open-source content management system (CMS) used to build and manage websites and applications. It is known for its flexibility and scalability, often used for complex and data-driven sites.
Websitehttps://www.drupal.org/ ↗
SECURITY POSTURE
Drupal's security posture has been historically problematic, with a recurring pattern of critical and high-severity remote code execution (RCE) vulnerabilities discovered in the core. These vulnerabilities have been actively exploited, impacting organizations.
Notable failures
- CVE-2018-7602 (critical RCE) - ransomware exploitation
- CVE-2018-7600 (critical RCE) - complete site compromise
- CVE-2026-9082 (high RCE) - SQL injection and privilege escalation
- CVE-2019-6340 (high RCE) - arbitrary PHP code execution
- CVE-2020-13671 (high RCE) - improper sanitization of file names
Patterns: Recurring critical and high-severity RCE vulnerabilities in Drupal Core; Improper data sanitization leading to code execution; Vulnerabilities actively exploited in ransomware attacks
FAILURE HISTORY · 7
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-13 | CVE-2018-7602 | critical | Drupal Core suffered a critical remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using the platform for web applications and content management. |
| 2022-03-25 | CVE-2019-6340 | high | Drupal Core's improper data sanitization allowed arbitrary PHP code execution via non-form sources. |
| 2022-01-18 | CVE-2020-13671 | high | Drupal core's improper extension file name sanitization allows un-restricted file uploads, enabling attackers to execute arbitrary code on vulnerable systems. |
| 2021-11-03 | CVE-2018-7600 | critical | A critical Drupal Core vulnerability allowed attackers to execute arbitrary code on compromised sites, actively exploited and linked to ransomware activity. |
| 2026-05-22 | CVE-2026-9082 | high | Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API. |
| 2018-07-19 | CVE-2018-7602 | critical | CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa |
| 2018-07-19 | CVE-2018-7602 | critical | CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-1.00
…
DOSSIER SOURCES
- Top Drupal Development Companies - 2026 Reviews | Goodfirms · www.goodfirms.co
- Usage Statistics and Market Share of Drupal, July 2026 - W3Techs · w3techs.com
- drupal 11.3.14 | Drupal.org · www.drupal.org
- Drupal 11.4.4, 11.3.14, and 10.6.13 Fix Three Security Issues · www.thedroptimes.com
- Update Drupal Core to 11.4.4 on the 11.0.x branch · www.drupal.org
Open questions: What is the current patching cadence for Drupal Core? · What security review processes are in place for Drupal Core releases? · What is the extent of third-party module vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:38:49.771495+00:00