SecAlerts
D

Drupal

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 20, 2009 to present

1000
Total CVEs
236
Critical+High
12
Exploited
83
Unpatched

Threat Assessment

Avg CVSS
5.6
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
83
Critical/High
Risk Level
39/100
low
⚠️ 12 Active Exploits📈 10 in Last 30 Days

Severity Distribution

Critical
108
High
128
Medium
530
Low
192

Exploit Likelihood

>50% chance
1
20-50%
0
5-20%
0
<5%
89

Age Distribution

Common Weaknesses (CWE)

1
XSS
396
2
CSRF
75
3
Infoleak
32
4
Input Validation
30
5
SQL Injection
23

Most Affected Products

1. Drupal Drupal5289
2. Ubercart Ubercart478
3. composer/drupal/core260
4. SpeedTech Storm222
5. Nathan Haug Webform196

Recent Vulnerabilities

See more →

Monitor Drupal in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.