Skip to content
COOEY

FAIL › dossier

Drupal core

PRODUCT

· dossier confidence 50%

Drupal core is a widely used open-source CMS with a documented history of critical RCE vulnerabilities, including CVE-2018-7600 actively exploited by ransomware and CVE-2020-13671 involving extension file name sanitization. Its security posture requires vigilant patching and extension vetting to mitigate RCE risks.

PROFILE
CategoryCMSWhat they doDrupal core is an open-source content management system (CMS) used for building websites and web applications.
SECURITY POSTURE

Drupal core has a history of critical remote code execution (RCE) vulnerabilities, including CVE-2018-7600 actively exploited by ransomware and CVE-2020-13671 involving improper sanitization of extension file names.

Notable failures
  • CVE-2018-7600 critical RCE exploited by ransomware
  • CVE-2020-13671 high RCE via improper extension sanitization
Patterns: repeated critical RCE vulnerabilities; improper input sanitization in extensions
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-01-18 CVE-2020-13671 high Drupal core's improper extension file name sanitization allows un-restricted file uploads, enabling attackers to execute arbitrary code on vulnerable systems.
2021-11-03 CVE-2018-7600 critical A critical Drupal Core vulnerability allowed attackers to execute arbitrary code on compromised sites, actively exploited and linked to ransomware activity.
Open questions: Are there additional CVEs beyond the two provided in the internal failure history? · What is the current patching SLA for Drupal core vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 03:58:47.901603+00:00