Skip to content
COOEY

FAIL › dossier

Drupal

VENDOR

· dossier confidence 33%

Drupal, a widely used open-source CMS, has a history of critical security vulnerabilities, including remote code execution flaws exploited in ransomware attacks. Regular updates and diligent security practices are essential for mitigating risk.

PROFILE
CategoryContent Management SystemWhat they doDrupal is an open-source content management system (CMS) used to build and manage websites and applications. It is known for its flexibility and scalability, often used for complex and data-driven sites. Websitehttps://www.drupal.org/ ↗
SECURITY POSTURE

Drupal's security posture has been historically problematic, with a recurring pattern of critical and high-severity remote code execution (RCE) vulnerabilities discovered in the core. These vulnerabilities have been actively exploited, impacting organizations.

Notable failures
  • CVE-2018-7602 (critical RCE) - ransomware exploitation
  • CVE-2018-7600 (critical RCE) - complete site compromise
  • CVE-2026-9082 (high RCE) - SQL injection and privilege escalation
  • CVE-2019-6340 (high RCE) - arbitrary PHP code execution
  • CVE-2020-13671 (high RCE) - improper sanitization of file names
Patterns: Recurring critical and high-severity RCE vulnerabilities in Drupal Core; Improper data sanitization leading to code execution; Vulnerabilities actively exploited in ransomware attacks
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2022-04-13 CVE-2018-7602 critical Drupal Core suffered a critical remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using the platform for web applications and content management.
2022-03-25 CVE-2019-6340 high Drupal Core's improper data sanitization allowed arbitrary PHP code execution via non-form sources.
2022-01-18 CVE-2020-13671 high Drupal core's improper extension file name sanitization allows un-restricted file uploads, enabling attackers to execute arbitrary code on vulnerable systems.
2021-11-03 CVE-2018-7600 critical A critical Drupal Core vulnerability allowed attackers to execute arbitrary code on compromised sites, actively exploited and linked to ransomware activity.
2026-05-22 CVE-2026-9082 high Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API.
2018-07-19 CVE-2018-7602 critical CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa
2018-07-19 CVE-2018-7602 critical CVE-2018-7602: A remote code execution vulnerability exists within multiple subsystems of Drupa
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-1.00
cooey ↗severe-fallout-1.00
"…"
Open questions: What is the current patching cadence for Drupal Core? · What security review processes are in place for Drupal Core releases? · What is the extent of third-party module vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:38:49.771495+00:00