Security Risk Category

Drupal Security Risks

Published vulnerability pages connected to Drupal. Each page keeps one canonical URL and focused remediation guidance.

6 published Drupal risks

Drupal risks

Showing 1–6 of 6 published risks.

highEPSS 0.003

CVE-2026-55809 in Drupal Flag attendance field

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.

CVE-2026-55809drupalunsafe-deserialization

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-55810 in Drupal Plotly.js Graphing

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

CVE-2026-55810drupalunsafe-deserialization

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58589 in Drupal FlowDrop

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

CVE-2026-58589drupalauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58590 in Drupal FlowDrop

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

CVE-2026-58590drupalauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58591 in Drupal Colorbox

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

CVE-2026-58591drupalxss

Updated Jul 15, 2026

criticalCISA KEVEPSS 0.846

Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVE-2026-9082drupalapi-securityremote-code-executionsql-injection

Updated Jul 9, 2026