https://www.drupal.org/project/drupal
Drupal core | Drupal.org
Dec 2, 2025 - Drupal is an open source content management platform supporting a variety of websites ranging from personal weblogs to large community-driven websites. Learn...
drupal core
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Theme/10
namespace Drupal\Core\Theme | Drupal API
drupal corenamespacethemeapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Entity%21Controller/10
namespace Drupal\Core\Entity\Controller | Drupal API
drupal corenamespaceentitycontrollerapi
https://www.drupal.org/about/core/policies/maintainers/release-notes
Writing release notes for Drupal core releases | Release management | About guide on Drupal.org
Jun 3, 2025 - Formatting, content, and process guidelines for release notes of core releases
release notesdrupal core
https://advisories.gitlab.com/composer/drupal/drupal/CVE-2024-55634/
Drupal core Access bypass | GitLab Advisory Database (GLAD)
CVE-2024-55634 Drupal core Access bypass: Drupal's uniqueness checking for certain user fields is inconsistent depending on the database engine and its...
drupal coreaccessbypassgitlabadvisory
https://www.drupal.org/community-initiatives/previousinactive-initiatives/views-in-drupal-core/views-in-drupal-core-vdc
Views in Drupal Core (VDC) | Views in Drupal Core | About guide on Drupal.org
Oct 6, 2020 - Views is in Drupal 8 core. At this stage in Drupal 8, most members of initiatives are helping across all initiatives, focusing on criticals
drupal coreabout guideviewsvdc
https://www.drupal.org/project/issues/drupal?categories=All
Issues for Drupal core | Drupal.org
drupal coreissues
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Plugin%21Context/10
namespace Drupal\Core\Plugin\Context | Drupal API
drupal corenamespaceplugincontextapi
https://www.drupal.org/sa-core-2019-012
Drupal core - Critical - Multiple vulnerabilities - SA-CORE-2019-012 | Drupal.org
Aug 21, 2022 - The Drupal project uses the third-party library Archive_Tar, which has released a security improvement that is needed to protect some Drupal configurations....
drupal corecriticalmultiplevulnerabilitiessa
https://www.drupal.org/sa-core-2021-008
Drupal core - Moderately critical - Access bypass - SA-CORE-2021-008 | Drupal.org
Aug 21, 2022 - Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an...
drupal corecritical accessmoderatelybypasssa
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Command/11.x
namespace Drupal\Core\Command | Drupal API
drupal corenamespacecommandapi
https://www.drupal.org/node/2281635
\Drupal\Core\Plugin\Context\Context should use a ContextDefinition class instead of arrays...
Jul 29, 2014 - Problem/Motivation The Context class currently uses an array to represent its definition. It almost exactly mimics the DataDefinition class, but is not...
drupal core
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Utility/10
namespace Drupal\Core\Utility | Drupal API
drupal corenamespaceutilityapi
https://www.drupal.org/sa-core-2019-004
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004 | Drupal.org
Aug 21, 2022 - Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
cross site scriptingdrupal coremoderatelycritical
https://www.drupal.org/docs/develop/issues/issue-procedures-and-etiquette/core-scope
Issue scope guidelines for Drupal core issues | Issue procedures and etiquette | Drupal Wiki guide...
Dec 31, 2025 - Guidelines for deciding what belongs in a single Drupal core issue
drupal core
https://www.drupal.org/node/3089526
jQuery UI source added to Drupal core and deprecated code removed | Drupal.org
Oct 19, 2022 - jQuery UI is being phased out of Drupal core, and most libraries were deprecated in 8.8 and moved to contributed modules. jQuery UI Sortable has been replaced...
jquery uidrupal core
https://advisories.gitlab.com/composer/drupal/drupal/GHSA-j66p-fvp2-fxhj/
Drupal core Arbitrary PHP code execution | GitLab Advisory Database (GLAD)
GHSA-j66p-fvp2-fxhj Drupal core Arbitrary PHP code execution: The Drupal project uses the PEAR Archive_Tar library. The PEAR Archive_Tar library has released a...
drupal corephp codearbitraryexecutiongitlab
https://www.drupal.org/sa-core-2025-008
Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 | Drupal.org
Nov 13, 2025 - The core system module handles downloads of private and temporary files. Contrib modules can define additional kinds of files (schemes) that may also be...
drupal corecritical informationmoderatelydisclosuresa
https://www.drupal.org/sa-core-2025-006
Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 | Drupal.org
Nov 13, 2025 - Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain"...
drupal coremoderatelycriticalgadgetchain
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Http%21Exception/10
namespace Drupal\Core\Http\Exception | Drupal API
drupal corenamespacehttpexceptionapi
https://advisories.gitlab.com/composer/drupal/drupal/GHSA-5x28-3f32-x523/
Drupal core Access control bypass | GitLab Advisory Database (GLAD)
GHSA-5x28-3f32-x523 Drupal core Access control bypass : The Media Library module has a security vulnerability whereby it doesn't sufficiently restrict access...
drupal coreaccess controlbypassgitlabadvisory
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Logger/8.9.x
namespace Drupal\Core\Logger | Drupal API
drupal corenamespaceloggerapi
https://advisories.gitlab.com/composer/drupal/core/CVE-2022-25273/
Improper input validation in Drupal core | GitLab Advisory Database (GLAD)
CVE-2022-25273 Improper input validation in Drupal core: Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be...
input validationdrupal coreimpropergitlabadvisory
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test%21RunTests/10
namespace Drupal\Core\Test\RunTests | Drupal API
drupal corenamespacetestapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21File/8.9.x
namespace Drupal\Core\File | Drupal API
drupal corenamespacefileapi
https://advisories.gitlab.com/composer/drupal/core/CVE-2023-31250/
Access bypass in Drupal core | GitLab Advisory Database (GLAD)
CVE-2023-31250 Access bypass in Drupal core: The file download facility does not sufficiently sanitize file paths in certain situations. This may result in...
drupal coreaccessbypassgitlabadvisory
https://www.drupal.org/project/dashboards/issues/3212165
Drupal\Core\Security\UntrustedCallbackException: Render #lazy_builder callbacks must be methods of...
May 20, 2021 - Problem/Motivation When adding the "Show rss news" block to the dashboard, an error occurs: Drupal\Core\Security\UntrustedCallbackException: Render...
drupal core
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Datetime/8.9.x
namespace Drupal\Core\Datetime | Drupal API
drupal corenamespacedatetimeapi
https://www.drupal.org/project/issues/drupal?categories=All&status=14
Issues for Drupal core | Drupal.org
drupal coreissues
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Theme/8.9.x
namespace Drupal\Core\Theme | Drupal API
drupal corenamespacethemeapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21TypedData%21Plugin%21DataType/9
namespace Drupal\Core\TypedData\Plugin\DataType | Drupal API
drupal corenamespaceplugindatatypeapi
https://www.drupal.org/sa-core-2026-002
Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 | Drupal.org
Apr 15, 2026 - Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget...
drupal coremoderatelycriticalgadgetchain
https://www.drupal.org/community/contributor-guide/role/drupal-core-leadership-team
Drupal Core Leadership Team | Drupal.org
core leadership teamdrupal
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Routing/8.9.x
namespace Drupal\Core\Routing | Drupal API
drupal corenamespaceroutingapi
https://advisories.gitlab.com/composer/drupal/drupal/CVE-2024-55638/
Drupal core contains a potential PHP Object Injection vulnerability | GitLab Advisory Database...
CVE-2024-55638 Drupal core contains a potential PHP Object Injection vulnerability: Drupal core contains a potential PHP Object Injection vulnerability that...
drupal core
https://advisories.gitlab.com/composer/drupal/core/CVE-2024-55638/
Drupal core contains a potential PHP Object Injection vulnerability | GitLab Advisory Database...
CVE-2024-55638 Drupal core contains a potential PHP Object Injection vulnerability: Drupal core contains a potential PHP Object Injection vulnerability that...
drupal core
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Cache/main
namespace Drupal\Core\Cache | Drupal API
drupal corenamespacecacheapi
https://www.drupal.org/community/contributor-guide/role/drupal-core-initiative-coordinator
Drupal core initiative coordinator | Drupal.org
drupal coreinitiativecoordinator
https://www.drupal.org/about/core
Drupal Core Development | Drupal.org
drupal coredevelopment
https://www.drupal.org/node/244637
SA-2008-026 - Drupal core - Access bypass | Drupal.org
Mar 10, 2009 - Advisory ID: DRUPAL-SA-2008-026 Project: Drupal core Version: 6.x Date: 2008-April-09 Security risk: Moderately critical Exploitable from: Remote...
drupal coresaaccessbypass
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21ParamConverter/10
namespace Drupal\Core\ParamConverter | Drupal API
drupal corenamespaceapi
https://www.drupal.org/project/drupal/issues/3466719
Drupal core committers meeting 2024-08-05 [#3466719] | Drupal.org
Jun 18, 2025 - Issue to capture participation in the core committers monthly meeting in Slack
drupal corecommittersmeeting
https://www.drupal.org/list-changes/drupal/published?keywords_description=new+experimental+module&to_branch=&version=&created_op=%3E%3D&created%5Bvalue%5D=&created%5Bmin%5D=&created%5Bmax%5D=
Change records for Drupal core | Drupal.org
change recordsdrupal core
https://advisories.gitlab.com/composer/drupal/core/CVE-2025-13080/
Drupal core allows Forceful Browsing | GitLab Advisory Database (GLAD)
CVE-2025-13080 Drupal core allows Forceful Browsing: Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful...
drupal coreallowsforcefulbrowsinggitlab
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Path/main
namespace Drupal\Core\Path | Drupal API
drupal corenamespacepathapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Render%21Element/9
namespace Drupal\Core\Render\Element | Drupal API
drupal corenamespacerenderelementapi
https://www.drupal.org/sa-core-2023-001
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001 | Drupal.org
Nov 22, 2024 - The Media Library module does not properly check entity access in some circumstances. This may result in users with access to edit content seeing metadata...
drupal corecritical informationmoderatelydisclosuresa
https://www.drupal.org/sa-core-2020-012
Drupal core - Critical - Remote code execution - SA-CORE-2020-012 | Drupal.org
Aug 21, 2022 - Update November 18: Documented longer list of dangerous file extensions Drupal core does not properly sanitize certain filenames on uploaded files, which can...
remote code executiondrupal corecriticalsa
https://advisories.gitlab.com/pkg/composer/drupal/core/GHSA-7f4f-p7mq-p4fv/
https://advisories.gitlab.com/composer/drupal/core/GHSA-7f4f-p7mq-p4fv/
drupal corehttpsadvisoriesgitlabcomposer
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Layout/11.x
namespace Drupal\Core\Layout | Drupal API
drupal corenamespacelayoutapi
https://www.drupal.org/node/3060/qa
Drupal core | Drupal.org
drupal core
https://www.drupal.org/sa-core-2018-002
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002 | Drupal.org
Aug 21, 2022 - A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack...
remote code executiondrupal corehighlycritical
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Form/main
namespace Drupal\Core\Form | Drupal API
drupal corenamespaceformapi
https://www.drupal.org/sa-core-2020-009
Drupal core - Critical - Cross-site scripting - SA-CORE-2020-009 | Drupal.org
Aug 21, 2022 - Drupal 8 and 9 have a reflected cross-site scripting (XSS) vulnerability under certain circumstances. An attacker could leverage the way that HTML is rendered...
cross site scriptingdrupal corecriticalsa
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Database%21Transaction/10
namespace Drupal\Core\Database\Transaction | Drupal API
drupal corenamespacedatabasetransactionapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Access/10
namespace Drupal\Core\Access | Drupal API
drupal corenamespaceaccessapi
https://www.drupal.org/project/issues/drupal?text=&status=Open&priorities=All&categories=All&version=All&component=documentation
Issues for Drupal core | Drupal.org
drupal coreissues
https://www.drupal.org/list-changes/3060/published
Change records for Drupal core | Drupal.org
change recordsdrupal core
https://www.drupal.org/sa-core-2018-006
Drupal Core - Multiple Vulnerabilities - SA-CORE-2018-006 | Drupal.org
Oct 28, 2024 - Advisory ID: DRUPAL-SA-CORE-2018-006 Project: Drupal core Version: 7.x, 8.x Date: 2018-October-17 Description Content moderation - Moderately critical - Access...
drupal coremultiplevulnerabilitiessa
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Annotation/9
namespace Drupal\Core\Annotation | Drupal API
drupal corenamespaceannotationapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Database%21Driver%21mysql/10
namespace Drupal\Core\Database\Driver\mysql | Drupal API
drupal corenamespacedatabasedrivermysql
https://www.drupal.org/project/drupal/issues/3457744
Drupal core committers team meeting - Dev Days Burgas 2024 [#3457744] | Drupal.org
Jun 18, 2025 - Issue to capture participation in the two-day Drupal core committer team meeting, June 24-25 in Burgas (and remotely) before Dev Days.
drupal coreteam meetingdev dayscommitters
https://www.drupal.org/node/66763
SA-2006-007 - Drupal Core - Revision to DRUPAL-SA-2006-006 | Drupal.org
Mar 10, 2009 - Advisory ID: DRUPAL-SA-2006-007 Project: Drupal core and potentially any web application that accepts uploads. Date: 2006-Jun-01 Security risk: highly critical...
drupal coresarevision
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test%21HttpClientMiddleware/9
namespace Drupal\Core\Test\HttpClientMiddleware | Drupal API
drupal corenamespacetestapi
https://packagist.org/packages/drupal/core-assertion
drupal/core-assertion - Packagist.org
Provides helper functionality for runtime assertions.
drupal coreassertionpackagist
https://www.drupal.org/sa-core-2022-002
Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002 | Drupal.org
Aug 21, 2022 - jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be...
cross site scriptingdrupal coremoderatelycritical
https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiple
Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-004 | Drupal.org
Aug 17, 2017 - Drupal 8.3.7 is a maintenance release which contain fixes for security vulnerabilities. Download Drupal 8.3.7 Updating your existing Drupal 8 sites is strongly...
drupal coremultiplevulnerabilitiessa
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Plugin/10
namespace Drupal\Core\Plugin | Drupal API
drupal corenamespacepluginapi
https://advisories.gitlab.com/composer/drupal/core/GHSA-vfgc-c76h-mwh4/
Drupal core Cross-Site Scripting (XSS) vulnerabilities | GitLab Advisory Database (GLAD)
GHSA-vfgc-c76h-mwh4 Drupal core Cross-Site Scripting (XSS) vulnerabilities: The Drupal project uses the CKEditor, library for WYSIWYG editing. CKEditor has...
cross site scriptingdrupal core
https://www.drupal.org/sa-core-2020-010
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2020-010 | Drupal.org
Aug 21, 2022 - Drupal core's built-in CKEditor image caption functionality is vulnerable to XSS.
cross site scriptingdrupal coremoderatelycritical
https://www.drupal.org/project/drupal/issues/3458405
Drupal core committers meeting 2024-06-11 [#3458405] | Drupal.org
Jun 18, 2025 - Issue to capture participation in the core committers monthly meeting in Slack
drupal corecommittersmeeting
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21FileTransfer/9
namespace Drupal\Core\FileTransfer | Drupal API
drupal corenamespacefiletransferapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21TypedData%21Type/9
namespace Drupal\Core\TypedData\Type | Drupal API
drupal corenamespacetypeapi
https://advisories.gitlab.com/composer/drupal/core/CVE-2025-13081/
Drupal core allows Object Injection | GitLab Advisory Database (GLAD)
CVE-2025-13081 Drupal core allows Object Injection: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal...
drupal coreallowsobjectinjectiongitlab
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Locale/11.x
namespace Drupal\Core\Locale | Drupal API
drupal corenamespacelocaleapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Plugin%21Definition/11.x
namespace Drupal\Core\Plugin\Definition | Drupal API
drupal corenamespaceplugindefinitionapi
https://www.drupal.org/security/core
Security advisories for Drupal core | Drupal.org
security advisoriesdrupal core
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Recipe/main
namespace Drupal\Core\Recipe | Drupal API
drupal corenamespacerecipeapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21ProxyClass%21Extension/9
namespace Drupal\Core\ProxyClass\Extension | Drupal API
drupal corenamespaceextensionapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Render%21Element/main
namespace Drupal\Core\Render\Element | Drupal API
drupal corenamespacerenderelementapi
https://www.drupal.org/project/drupal/issues/3484404
Drupal\Core\Datetime::dateFormat() does not properly cache results [#3484404] | Drupal.org
Nov 13, 2024 - Problem/Motivation I have a page that displays a series of calendar events, where each event has a start and end date. I found that having just a dozen or so...
drupal coredoes notdatetimedateformat
https://advisories.gitlab.com/composer/drupal/core/CVE-2025-31673/
Drupal Core Vulnerable to Forceful Browsing | GitLab Advisory Database (GLAD)
CVE-2025-31673 Drupal Core Vulnerable to Forceful Browsing: Incorrect Authorization vulnerability in Drupal core allows Forceful Browsing.This issue affects...
drupal corevulnerableforcefulbrowsinggitlab
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Entity%21Plugin%21Condition%21Deriver/main
namespace Drupal\Core\Entity\Plugin\Condition\Deriver | Drupal API
drupal corenamespaceentityplugincondition
https://www.drupal.org/sa-core-2020-003
Drupal core - Moderately critical - Open Redirect - SA-CORE-2020-003 | Drupal.org
Aug 21, 2022 - Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an...
drupal coreopen redirectmoderatelycriticalsa
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21TypedData%21Plugin%21DataType/main
namespace Drupal\Core\TypedData\Plugin\DataType | Drupal API
drupal corenamespaceplugindatatypeapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test/main
namespace Drupal\Core\Test | Drupal API
drupal corenamespacetestapi
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Security/10
namespace Drupal\Core\Security | Drupal API
drupal corenamespacesecurityapi
https://www.drupal.org/sa-core-2026-001
Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 | Drupal.org
Apr 15, 2026 - Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which which can lead to a cross-site scripting...
cross site scriptingdrupal corecriticalsa
https://dev.to/jcandan/full-width-drupal-core-remote-video-with-youtube-parameters-12kf
Full-width, Drupal core Remote Video with YouTube parameters - DEV Community
Drupal core supplies us a Remote Video media type. To display Media items of this type in a block,... Tagged with ai, learning, career.
full widthdrupal coreremote video
https://www.drupal.org/sa-core-2019-003
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003 | Drupal.org
Aug 21, 2022 - Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. A site is only affected by...
remote code executiondrupal corehighlycritical
https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test/10
namespace Drupal\Core\Test | Drupal API
drupal corenamespacetestapi
https://www.drupal.org/about/core/policies/core-change-policies/experimental/policy-and-list
Experimental modules and themes in Drupal core | Experimental modules and themes | About guide on...
Apr 14, 2026 - Introduction to experimental modules and themes, and a list of them currently in development
modules and themesdrupal coreabout guideexperimental
https://advisories.gitlab.com/composer/drupal/core-recommended/CVE-2024-55637/
Drupal core contains a potential PHP Object Injection vulnerability | GitLab Advisory Database...
CVE-2024-55637 Drupal core contains a potential PHP Object Injection vulnerability: Drupal core contains a potential PHP Object Injection vulnerability that...
drupal core
https://www.drupal.org/sa-core-2020-002
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002 | Drupal.org
Aug 21, 2022 - The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the...
cross site scriptingdrupal coremoderatelycritical
https://www.drupal.org/psa-2018-002
Drupal Core - Highly Critical - Public Service announcement - PSA-2018-002 | Drupal.org
Sep 16, 2019 - Project: Drupal core Version: 7.x, 8.x Description This Public Service Announcement is a follow-up to SA-CORE-2018-002 - Drupal core - RCE. This is not an...
public service announcementdrupal corehighlycritical
https://groups.drupal.org/node/430073
This month in Drupal Core (June 25, 2014) | Drupal Groups
this month indrupal corejunegroups
https://packagist.org/packages/drupal/core-php-storage
drupal/core-php-storage - Packagist.org
drupal corephpstoragepackagist
https://advisories.gitlab.com/composer/drupal/core/CVE-2024-11942/
Drupal core vulnerable to improper error handling | GitLab Advisory Database (GLAD)
CVE-2024-11942 Drupal core vulnerable to improper error handling: Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some...
drupal coreerror handlingvulnerableimproper
https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-04-19/drupal-core-critical-access-bypass
Drupal Core - Critical - Access Bypass - SA-CORE-2017-002 | Drupal.org
Apr 21, 2017 - Advisory ID: DRUPAL-SA-CORE-2017-002 Project: Drupal core Version: 8.x Date: 2017-April-19 CVEID: CVE-2017-6919 Security risk: 17/25 ( Critical)...
drupal corecritical accessbypasssa
https://advisories.gitlab.com/composer/drupal/drupal/GHSA-jf8c-36vw-98x4/
Drupal core Remote Code Execution | GitLab Advisory Database (GLAD)
GHSA-jf8c-36vw-98x4 Drupal core Remote Code Execution: In Drupal core, when sending email some variables were not being sanitized for shell arguments in...
remote code executiondrupal coregitlabadvisorydatabase