Drupal Core SQL Injection Vulnerability
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CISA entryDrupal · AUTOMATIC DISCOVERY
Drupal is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
Drupal is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used to provide application, infrastructure or operational services to other systems and users.
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Drupal |
|---|---|
| Release | Product policy |
| End of Support | 9 December 2026 |
| Date precision | Day |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CISA entryA remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CISA entryIn Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
CISA entryImproper sanitization in the extension file names is present in Drupal core.
CISA entryDrupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CISA entryOSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
Drupal 12 will be released on the week of December 7, 2026. Contributions to related issues will help ensure that we meet our goals. | Drupal 10 end of life | Drupal 10.6.0 is the last minor release of Drupal 10. | Drupal 10 will reach end of life on December 9, 2026. This is the same week that Drupal 12 will be released. No new releases of Drupal 10 will be made after this date. | Drupal 7 end of life | Drupal 7 is now end of life. Supported ended on January 5, 2025. | Read the security advisory for more details: End of life announcement and changes to Drupal 7 support - PSA-2023-06-07 . Check out the Drupal 7 end of life resource center for migration and long term support options.
Publisher identity used by product-specific official-source collectors.
Open official vendor source