Known vulnerabilities in Drupal Drupal 8.6.15

Vendor: Drupal
Website: https://www.drupal.org
Total Security Bulletins: 19

Security bulletins (19)

Secuity bulletin Severity Status Published
SB2025111349: Multiple vulnerabilities in Drupal Medium
Patched
13.11.2025
SB2025032012: Cross-site scripting in Drupal Low
Patched
20.03.2025
SB2025022002: Multiple vulnerabilities in Drupal Medium
Patched
20.02.2025
SB2024112110: Multiple vulnerabilities in Drupal Low
Patched
21.11.2024
SB2024112109: Multiple vulnerabilities in Drupal Low
Patched
21.11.2024
SB2024011787: Denial of service in Drupal Comment module Medium
Patched
17.01.2024
SB2023031541: Multiple vulnerabilities in Drupal Medium
Patched
15.03.2023
SB20230118103: Improper access control in Drupal Media Library Low
Patched
18.01.2023
SB2022092840: Path traversal in Drupal Twig Medium
Patched
28.09.2022
SB2022021627: Multiple vulnerabilities in Drupal Medium
Patched
16.02.2022
SB2022011943: XSS in Drupal (jQuery UI component) Medium
Patched
19.01.2022
SB2021072167: Drupal update for Archive_Tar library High
Patched
21.07.2021
SB2021012113: Remote code execution in pear Archive_Tar library in Drupal High
Patched Exploited
21.01.2021
SB2020112608: Remote code execution in Drupal High
Patched Exploited
26.11.2020
SB2020111827: Arbitrary file upload in Drupal High
Patched Exploited
18.11.2020
SB2020091701: Multiple vulnerabilities in Drupal Medium
Patched
17.09.2020
SB2020061807: Multiple vulnerabilities in Drupal High
Patched
18.06.2020
SB2019050909: Insecure deserialization in Drupal implementation of Phar Stream Wrapper Interceptor High
Patched
09.05.2019