Drupal is an open source content management platform powering millions of websites and applications.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10862 drupal/core is vulnerable to SQL Injection in versions 8.9.0 - 10.4.9, 10.5.0 - 10.5.9, 10.6.0 - 10.6.8, 11.0.0 - 11.1.9, 11.2.0 - 11.2.11 and 11.3.0 - 11.3.9. | 8.9.0 - 10.4.910.5.0 - 10.5.910.6.0 - 10.6.8 +3 more | |
AIKIDO-2026-10648 drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 8.0.0 - 10.5.8, 10.6.0 - 10.6.6, 11.0.0 - 11.2.10 and 11.3.0 - 11.3.6. | 8.0.0 - 10.5.810.6.0 - 10.6.611.0.0 - 11.2.10 +1 more | |
AIKIDO-2026-10569 drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.3.0 - 11.3.6. | 11.3.0 - 11.3.6 | |
AIKIDO-2026-10568 drupal/core is vulnerable to Deserialization of Untrusted Data in versions 8.0.0 - 10.5.8, 10.6.0 - 10.6.6, 11.0.0 - 11.2.10 and 11.3.0 - 11.3.6. | 8.0.0 - 10.5.810.6.0 - 10.6.611.0.0 - 11.2.10 +1 more | |
AIKIDO-2025-10812 drupal/core is vulnerable to Denial of Service (DoS) in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7. | 8.0.0 - 10.4.810.5.0 - 10.5.511.0.0 - 11.1.8 +1 more |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.27.0 | — | — |
mck89/peast Version ^1.17.4 | — | — |
symfony/mime Version ^7.4.12 | — | — |
symfony/yaml Version ^7.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant