Skip to main content

Drupal Multiple Vulnerabilities

Release Date: 23 Jun 2026 354 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in Drupal Core. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, spoofing, sensitive information disclosure, remote code execution and data manipulation on the targeted system.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Data Manipulation
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Drupal version prior to 10.5.12
  • Drupal version 10.6.x prior to 10.6.11
  • Drupal version 11.2.x prior to 11.2.14
  • Drupal version 11.3.x prior to 11.3.12
  • Drupal version 11.0.*
  • Drupal version 11.1.*

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.
 

Apply fixes issued by the vendor:

  • For Drupal 10.5.x, update to Drupal 10.5.12.
  • For Drupal 10.6.x, update to Drupal 10.6.11.
  • For Drupal 11.2.x, update to Drupal 11.2.14.
  • For Drupal 11.3.x, update to Drupal 11.3.12.

 

Note: All versions of Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)


Vulnerability Identifier


Source


Related Link