boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Drupal

Vendor reference — Drupal · sector: Open Source Ecosystems. Cumulative disclosure record across the archive.

Follow Drupal — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs5651
KEV entries51
Rate & severity
KEV/100Med CVSSMed EPSSCHML
8.95.9.001876355

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁█▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-055
2026-060
2026-0746
2026-080

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2018-7600100.0YES2021-11-03
CVE-2018-76029.899.9CRITICALYES2022-04-13
CVE-2019-634099.8YES2022-03-25
CVE-2026-90829.899.8CRITICALYES2026-05-22
CVE-2020-1367190.5YES2022-01-18
CVE-2026-107689.867.3CRITICAL2026-07-10
CVE-2026-125359.832.0CRITICAL2026-07-10
CVE-2026-68165.124.9MEDIUM2026-05-28
CVE-2026-119139.824.9CRITICAL2026-07-10
CVE-2026-97269.824.2CRITICAL2026-07-10
CVE-2026-558098.123.4HIGH2026-07-10
CVE-2026-150899.122.4CRITICAL2026-07-10
CVE-2026-150865.920.1MEDIUM2026-07-10
CVE-2025-83617.619.4HIGH2025-08-15
CVE-2026-53437.417.5HIGH2026-05-28

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-97269.824.2CRITICAL2026-07-10
CVE-2026-585915.43.5MEDIUM2026-07-10
CVE-2026-585905.43.9MEDIUM2026-07-10
CVE-2026-585895.43.9MEDIUM2026-07-10
CVE-2026-585886.14.9MEDIUM2026-07-10
CVE-2026-585876.14.6MEDIUM2026-07-10
CVE-2026-558108.116.4HIGH2026-07-10
CVE-2026-558098.123.4HIGH2026-07-10
CVE-2026-558085.45.8MEDIUM2026-07-10
CVE-2026-558073.13.9LOW2026-07-10
CVE-2026-558065.911.0MEDIUM2026-07-10
CVE-2026-558045.912.2MEDIUM2026-07-10
CVE-2026-558035.912.2MEDIUM2026-07-10
CVE-2026-150899.122.4CRITICAL2026-07-10
CVE-2026-150875.915.9MEDIUM2026-07-10

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Drupal Core83
AI (Artificial Intelligence)20
AI Agents20
Advanced Content Feedback (aka Admin_feedback)20
Core22
Drupal Canvas20
FlowDrop20
Paragraphs20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-90822026-05-229.899.8CRITICAL
CVE-2018-76022022-04-139.899.9CRITICAL
CVE-2019-63402022-03-2599.8
CVE-2020-136712022-01-1890.5
CVE-2018-76002021-11-03100.0

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2019-63402022-04-151587
CVE-2018-76002022-05-031569
CVE-2018-76022022-05-041568
CVE-2020-136712022-07-181493
CVE-2026-90822026-05-2784

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.