drupal has 4 CVEs on record between 2018 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.9 (medium), with 1 rated critical. The most common weakness class is CWE-119 (3). Most affected products: Gammu SMS Daemon (3), drupal (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 25% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —(1)
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2018-7602Critical· 9.8A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x100CVE-2026-76757Medium· 5.9Vulnerability in Drupal Gammu SMS Daemon32CVE-2026-76756Medium· 5.9Vulnerability in Drupal Gammu SMS Daemon32CVE-2026-76755Medium· 5.9Vulnerability in Drupal Gammu SMS Daemon32
drupal vulnerabilities
CVEs affecting drupal, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-76757Medium· 5.9Vulnerability in Drupal Gammu SMS Daemon
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76755Medium· 5.9Vulnerability in Drupal Gammu SMS Daemon
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76756Medium· 5.9Vulnerability in Drupal Gammu SMS Daemon
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2018-7602Critical· 9.8CISA KEVPoCA remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This …