Drupal is an open source content management platform powering millions of websites and applications.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10812 drupal/core is vulnerable to Denial of Service (DoS) in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7. | 8.0.0 - 10.4.810.5.0 - 10.5.511.0.0 - 11.1.8 +1 more | Medium |
AIKIDO-2025-10813 drupal/core is vulnerable to Deserialization of Untrusted Data in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7. | 8.0.0 - 10.4.810.5.0 - 10.5.511.0.0 - 11.1.8 +1 more | Medium |
AIKIDO-2025-10814 drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7. | 8.0.0 - 10.4.810.5.0 - 10.5.511.0.0 - 11.1.8 +1 more | Medium |
AIKIDO-2025-10815 drupal/core is vulnerable to Information Disclosure in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7. | 8.0.0 - 10.4.810.5.0 - 10.5.511.0.0 - 11.1.8 +1 more | Medium |
CVE-2025-31675 drupal/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 8.0.0 - 10.3.14, 10.4.0 - 10.4.5, 11.0.0 - 11.0.13 and 11.1.0 - 11.1.5. | 8.0.0 - 10.3.1410.4.0 - 10.4.511.0.0 - 11.0.13 +1 more | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.21.0 | — | — |
mck89/peast Version ^1.17.4 | — | — |
symfony/mime Version ^7.4 | — | — |
symfony/yaml Version ^7.4 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant