Drupal is an open source content management platform powering millions of websites and applications.
90%
Total Score
100
33
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-869158 New drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 10.6.12, 11.0.0 - 11.3.13 and 11.4.0 - 11.4.3. | 0.0.1 - 10.6.1211.0.0 - 11.3.1311.4.0 - 11.4.3 | Medium |
AIKIDO-2026-357148 New drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.2.0 - 11.3.13 and 11.4.0 - 11.4.3. | 11.2.0 - 11.3.1311.4.0 - 11.4.3 | Medium |
AIKIDO-2026-186793 New drupal/core is vulnerable to Information Disclosure in versions 0.0.0 - 10.6.12, 11.0.0 - 11.3.13 and 11.4.0 - 11.4.3. | 0.0.0 - 10.6.1211.0.0 - 11.3.1311.4.0 - 11.4.3 | Medium |
AIKIDO-2026-543762 drupal/core is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11. | 0.0.0 - 10.5.1110.6.0 - 10.6.1011.0.0 - 11.2.13 +1 more | High |
AIKIDO-2026-34610 drupal/core is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11. | 0.0.0 - 10.5.1110.6.0 - 10.6.1011.0.0 - 11.2.13 +1 more | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.27.0 | — | — |
mck89/peast Version ^1.17.4 | — | — |
symfony/mime Version ^7.4.12 | — | — |
symfony/yaml Version ^7.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant