FAIL › dossier
Drupal core
PRODUCT· dossier confidence 50%
Drupal core is a widely used open-source CMS with a documented history of critical RCE vulnerabilities, including CVE-2018-7600 actively exploited by ransomware and CVE-2020-13671 involving extension file name sanitization. Its security posture requires vigilant patching and extension vetting to mitigate RCE risks.
PROFILE
CategoryCMSWhat they doDrupal core is an open-source content management system (CMS) used for building websites and web applications.
SECURITY POSTURE
Drupal core has a history of critical remote code execution (RCE) vulnerabilities, including CVE-2018-7600 actively exploited by ransomware and CVE-2020-13671 involving improper sanitization of extension file names.
Notable failures
- CVE-2018-7600 critical RCE exploited by ransomware
- CVE-2020-13671 high RCE via improper extension sanitization
Patterns: repeated critical RCE vulnerabilities; improper input sanitization in extensions
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-01-18 | CVE-2020-13671 | high | Drupal core's improper extension file name sanitization allows un-restricted file uploads, enabling attackers to execute arbitrary code on vulnerable systems. |
| 2021-11-03 | CVE-2018-7600 | critical | A critical Drupal Core vulnerability allowed attackers to execute arbitrary code on compromised sites, actively exploited and linked to ransomware activity. |
Open questions: Are there additional CVEs beyond the two provided in the internal failure history? · What is the current patching SLA for Drupal core vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 03:58:47.901603+00:00