Drupal vulnerability statistics in 2026 tell a more nuanced story than a single CVE count can show. Drupal’s official records separate vulnerabilities in Drupal core from security advisories affecting community-contributed modules and projects, while third-party CVE databases apply different inclusion rules. In 2026, Drupal published 12 core security advisories, most rated Moderately Critical, while contributed-project advisories continued to account for most of the ecosystem’s disclosed security issues. This report separates those datasets and tracks severity, vulnerability type, exploitation, Drupalgeddon incidents, market exposure, and supported versions.
QUICK ANSWERDrupal’s official 2026 records show 12 core security advisories, while the project’s year-to-date track-record table lists 73 contributed-project advisories. Eight of the 12 core advisories are Moderately Critical, four involve cross-site scripting, and CVE-2026-9082 became the year’s standout issue after Drupal confirmed exploitation attempts in the wild.
Drupal Vulnerability Statistics: Key Findings for 2026
The most useful Drupal security numbers are not one all-time CVE total. They distinguish Drupal core, contributed projects, known exploitation, current severity, and the population of websites potentially exposed.
| Drupal security statistic | Current figure | What it measures |
|---|---|---|
| Drupal core advisories in 2026 | 12 | Official SA-CORE advisories published in 2026 |
| Contributed-project advisories in Drupal’s official 2026 track-record snapshot | 73 | SA-CONTRIB advisories in the project’s published year-to-date table; more advisories have appeared since that snapshot |
| 2026 core advisories rated Moderately Critical | 8 of 12 — 66.7% | Drupal’s own 0–25 security risk scale |
| 2026 core advisories labeled XSS | 4 of 12 — 33.3% | Official Drupal advisory titles |
| Highest-profile 2026 core vulnerability | CVE-2026-9082 | PostgreSQL-specific SQL injection, currently rated 23/25 and exploited in the wild |
| Drupal core CVEs represented in CISA KEV | At least 5 major entries | Confirmed known exploitation rather than theoretical severity alone |
| Drupal usage across all websites | 0.6% | W3Techs, September 12, 2026 |
| Drupal share among websites with a known CMS | 0.9% | W3Techs, September 12, 2026 |
| Drupal share among top-10,000 sites with a known CMS | 6.7% | W3Techs traffic-ranking breakdown |
DO NOT COMPARE DRUPAL NUMBERS WITHOUT CHECKING THE DENOMINATORA Drupal security advisory, a Drupal core CVE, a contributed-module CVE, and a third-party vulnerability-database record are not interchangeable units. Two trustworthy databases can report different totals because they are counting different things.
What Counts as a Drupal Vulnerability?
The phrase “Drupal vulnerability” can refer to several different populations of security issues. Understanding those populations is necessary before comparing statistics.
| Record type | What it covers | Typical identifier |
|---|---|---|
| Drupal core advisory | A security issue in the main Drupal core software | SA-CORE-YYYY-NNN |
| Contributed-project advisory | A module, theme, distribution, or other community-contributed project | SA-CONTRIB-YYYY-NNN |
| CVE | A vulnerability assigned a Common Vulnerabilities and Exposures identifier | CVE-YYYY-NNNN |
| CISA KEV entry | A CVE with confirmed evidence of real-world exploitation | CVE listed in the Known Exploited Vulnerabilities catalog |
| Third-party database record | A vendor-defined or database-defined Drupal product or component population | Varies by database |
This distinction matters because Drupal is itself a CVE Numbering Authority, or CNA. Its current policy says CVEs are generally assigned to Drupal core and contributed projects that qualify for a security advisory and have more than 10,000 reported installs, although CVEs can also be issued in other cases.
That means:
Drupal security advisory
≠
Drupal CVE
≠
Drupal core vulnerability
≠
Contributed-module vulnerability
≠
Third-party database record
Why Do Drupal Vulnerability Counts Differ Between Databases?
This is the most important methodological issue in Drupal vulnerability statistics.
Different security databases currently give very different 2026 numbers because they define “Drupal” differently. Some count only CVEs mapped directly to Drupal core. Others include contributed modules, older Drupal 7 projects, dependency records, or multiple product names associated with the Drupal vendor.
| Source | Example 2026 result | What appears to be counted |
|---|---|---|
| Drupal Security Team | 12 core + 73 contributed in its official year-to-date track-record table | Drupal security advisories, separated by core and contributed projects |
| RadicalNotion | 9 Drupal core CVEs | Drupal core CVE records |
| Stack.watch | Different Drupal product views expose different 2026 totals | Records grouped according to product/vendor mappings in its CVE dataset |
| Patchstack | Drupal core vulnerability history | Patchstack’s Drupal core vulnerability dataset |
| CVE databases | Varies | Records linked through CVE/CPE vendor and product data |
None of those figures should automatically be described as “the number of Drupal vulnerabilities.” The correct wording has to include the dataset.
For example:
“Drupal published 12 core security advisories in 2026” is a precise statement.
But:
“Drupal has 12 vulnerabilities in 2026” is ambiguous because it excludes the contributed-project ecosystem and may not match CVE databases.
How Many Drupal Security Advisories Are Published Each Year?
Drupal’s official Security Team maintains one of the strongest datasets for historical comparison because it uses the same broad distinction between core and contributed projects across many years.
| Year | Core advisories | Contributed-project advisories | Total in official table |
|---|---|---|---|
| 2026 YTD | 12 | 73 | 85 |
| 2025 | 8 | 113 | 121 |
| 2024 | 8 | 76 | 84 |
| 2023 | 6 | 55 | 61 |
| 2022 | 15 | 63 | 78 |
| 2021 | 11 | 46 | 57 |
| 2020 | 13 | 38 | 51 |
| 2019 | 12 | 96 | 108 |
| 2018 | 6 | 81 | 87 |
| 2017 | 4 | 97 | 101 |
The long-term pattern is clear: contributed-project advisories greatly outnumber Drupal core advisories.
Drupal’s published annual series runs back to 2005. Summing that official table through its current 2026 year-to-date row gives 1,927 security advisories: 171 for core and 1,756 for contributed projects. On that specific dataset, contributed projects account for about 91.1% of all listed advisories.
IMPORTANTThat 91.1% figure describes Drupal.org’s security-advisory dataset. It does not mean 91.1% of vulnerabilities on every real Drupal website come from contributed modules, and it should not be substituted for site-level vulnerability telemetry.
Drupal Core vs Contributed-Module Vulnerabilities

Contributed projects consistently create a much larger disclosure population than Drupal core.
| Year | Core | Contributed | Contributed share of official advisories |
|---|---|---|---|
| 2026 YTD snapshot | 12 | 73 | 85.9% |
| 2025 | 8 | 113 | 93.4% |
| 2024 | 8 | 76 | 90.5% |
| 2023 | 6 | 55 | 90.2% |
| 2022 | 15 | 63 | 80.8% |
This does not prove Drupal core is “safe” or contributed modules are inherently insecure. Drupal core and the contributed ecosystem are very different software populations. There are many more contributed projects, they are maintained by different teams, and their installation bases vary widely.
The operational lesson is simpler: a fully patched Drupal core does not tell you whether every installed module is secure or supported.
Drupal Core Vulnerabilities by Severity in 2026

Drupal does not use CVSS as its primary advisory severity system. The Drupal Security Team scores advisories from 0 to 25 using a system based on NIST’s Common Misuse Scoring System.
The current bands are:
- 0–4: Not Critical
- 5–9: Less Critical
- 10–14: Moderately Critical
- 15–19: Critical
- 20–25: Highly Critical
Among the 12 Drupal core advisories published in 2026:
| Drupal severity | 2026 core advisories | Share |
|---|---|---|
| Highly Critical | 1 | 8.3% |
| Critical | 2 | 16.7% |
| Moderately Critical | 8 | 66.7% |
| Less Critical | 1 | 8.3% |
| Not Critical | 0 | 0% |
So the most common Drupal core severity in 2026 is Moderately Critical, not Critical or Highly Critical.
That also demonstrates why a handful of famous incidents can distort Drupal’s reputation. The exceptional vulnerabilities receive the headlines, while most ordinary core advisories sit in the middle of Drupal’s risk scale.
Drupal Core Vulnerabilities by Type in 2026

The official 2026 core advisory titles also provide a clean current-year view of vulnerability classes.
| Vulnerability type | 2026 core advisories | Share of 12 advisories |
|---|---|---|
| Cross-site scripting (XSS) | 4 | 33.3% |
| Gadget chain | 2 | 16.7% |
| SQL injection | 1 | 8.3% |
| PHP object injection | 1 | 8.3% |
| Cache poisoning / open redirect | 1 | 8.3% |
| Server-side request forgery | 1 | 8.3% |
| Improper validation | 1 | 8.3% |
| Information disclosure | 1 | 8.3% |
XSS is therefore the most frequent vulnerability label in Drupal core’s 2026 advisory set, appearing in four of the 12 advisories.
That should not be interpreted as evidence that XSS is automatically the biggest Drupal risk. Frequency and impact are different measurements. The only Highly Critical core advisory of 2026 is an SQL injection vulnerability, CVE-2026-9082.
Which Drupal Vulnerabilities Are Known to Be Exploited?
Severity tells you how damaging a vulnerability could be. CISA’s Known Exploited Vulnerabilities catalog answers a different question: whether there is evidence attackers have actually exploited the vulnerability in the wild.
Major Drupal core CVEs represented in CISA KEV include:
| CVE | Year | Vulnerability | Known exploitation |
|---|---|---|---|
| CVE-2018-7600 | 2018 | Remote code execution — Drupalgeddon2 | CISA KEV; linked to ransomware campaigns |
| CVE-2018-7602 | 2018 | Remote code execution — often called Drupalgeddon3 | CISA KEV; linked to ransomware campaigns |
| CVE-2019-6340 | 2019 | Remote code execution | CISA KEV |
| CVE-2020-13671 | 2020 | Improper file-extension sanitization / unrestricted upload | CISA KEV |
| CVE-2026-9082 | 2026 | SQL injection in Drupal core | CISA KEV; exploitation attempts confirmed by Drupal |
This is a small subset of the vulnerabilities disclosed over Drupal’s history, which illustrates why raw vulnerability counts and real-world exploitation should be analyzed separately.
How Fast Are Major Drupal Vulnerabilities Exploited?

There is no defensible universal statistic saying that every Drupal vulnerability is exploited within a fixed number of hours. Real incidents have produced very different timelines.
The better measurement is the observed disclosure-to-exploitation timeline for individual high-impact vulnerabilities.
| Vulnerability | Patch / disclosure | Observed attack signal | Approximate window |
|---|---|---|---|
| CVE-2014-3704 | October 15, 2014 | Drupal said sites not patched within seven hours should be considered likely compromised | <7 hours |
| CVE-2018-7600 | March 28, 2018 | Evidence of automated attacks by April 11 | About 14 days |
| CVE-2019-6340 | February 20, 2019 | Attack activity observed February 23 | About 3 days |
| CVE-2026-9082 | May 20, 2026 | Drupal updated the advisory on May 22 after exploitation attempts were detected | About 2 days |
THESE ARE INCIDENT TIMELINES, NOT A UNIVERSAL AVERAGEThe examples show that serious Drupal flaws can move from disclosure to exploitation very quickly. They do not prove that every Drupal vulnerability will be weaponized within the same time period.
The Biggest Drupal Vulnerabilities in History
Drupal’s security reputation is heavily influenced by a small number of unusually severe vulnerabilities. The best-known incidents are commonly grouped under the “Drupalgeddon” name.
| Incident | CVE | Year | Primary issue | Why it matters |
|---|---|---|---|---|
| Drupalgeddon | CVE-2014-3704 | 2014 | SQL injection | Automated compromises began within hours |
| Drupalgeddon2 | CVE-2018-7600 | 2018 | Remote code execution | Unauthenticated compromise affecting Drupal 6, 7 and 8; later mass exploitation |
| Drupalgeddon3 | CVE-2018-7602 | 2018 | Remote code execution | Follow-on RCE discovered shortly after Drupalgeddon2 |
| Drupal RCE | CVE-2019-6340 | 2019 | Remote code execution | Attacks observed only three days after the fix |
| 2026 SQL injection | CVE-2026-9082 | 2026 | SQL injection | Exploit attempts confirmed two days after disclosure |
Drupalgeddon — CVE-2014-3704
The original Drupalgeddon was an unauthenticated SQL injection vulnerability affecting Drupal 7. Its significance is less about a modern CVSS score and more about the exploitation timeline. Drupal’s own post-incident guidance said systematic attacks started so quickly that websites not patched within seven hours of the announcement should be considered likely compromised.
That remains one of the clearest historical examples of why internet-facing CMS vulnerabilities can create extremely short patch windows.
Drupalgeddon2 — CVE-2018-7600
CVE-2018-7600 was an unauthenticated remote code execution vulnerability disclosed in March 2018. It affected Drupal 6, Drupal 7, and Drupal 8 and became one of Drupal’s most widely exploited vulnerabilities.
Drupal later warned that automated attacks were underway and increased its risk score to 24/25. CISA now lists CVE-2018-7600 in the Known Exploited Vulnerabilities catalog and marks it as associated with ransomware campaigns.
Drupalgeddon3 — CVE-2018-7602
CVE-2018-7602 followed only weeks after Drupalgeddon2. It was another remote code execution vulnerability involving multiple Drupal subsystems. CISA also lists this flaw as known exploited and associated with ransomware campaigns.
CVE-2026-9082: Drupal’s Major 2026 Vulnerability
CVE-2026-9082 is the standout Drupal core vulnerability of 2026.
Disclosed on May 20 as SA-CORE-2026-004, it affects Drupal’s database abstraction layer on websites using PostgreSQL. An anonymous attacker can send specially crafted requests that result in SQL injection, potentially leading to information disclosure, privilege escalation, remote code execution, or other attacks.
The vulnerability was initially announced at 20/25 — Highly Critical while the exploit status was theoretical.
That changed rapidly.
May 20, 2026
Drupal publishes SA-CORE-2026-004
Risk score: 20/25
Exploit status: Theoretical
↓
May 22, 2026
Exploit attempts detected in the wild
↓
Drupal updates risk score
23/25 — Highly Critical
E:Exploit
↓
CVE-2026-9082 added to CISA KEV
The current official Drupal risk score is therefore 23/25, not the original 20/25.
This is also a useful example of why security statistics need retrieval dates. A vulnerability’s exploitation status, EPSS score, vendor risk rating, and KEV status can change after initial publication.
How Widely Is Drupal Used in 2026?
Drupal has a relatively small share of the total web but a stronger presence among high-traffic websites.
W3Techs reported on September 12, 2026 that Drupal is used by:
- 0.6% of all websites
- 0.9% of websites with a known CMS
- 3.6% of top-1-million sites whose CMS is known
- 6.1% of top-100,000 sites whose CMS is known
- 6.7% of top-10,000 sites whose CMS is known
The denominator in that last number matters. It does not mean 6.7% of every website in the global top 10,000 uses Drupal. It means 6.7% of top-10,000 websites whose CMS W3Techs identifies use Drupal.
For cross-platform context, see ScanTitan’s CMS Vulnerability Statistics research rather than comparing raw Drupal, WordPress, and Joomla CVE counts without accounting for different ecosystems and counting methods.
Which Drupal Versions Are Still Supported?
Drupal support status changes as new minor and major branches are released, so this is another statistic that must be dated.
As of September 2026, the Drupal core security release window covers:
| Drupal branch | Status in September 2026 | Security releases |
|---|---|---|
| 11.4.x | Supported | Yes |
| 11.3.x | Supported | Yes |
| 10.6.x | Supported | Yes |
| 11.2.x and older 11.x minors | End of security support | No regular security coverage |
| 10.5.x and older 10.x minors | End of security support | No regular security coverage |
| Drupal 9, 8 and 7 | End of life | No regular Drupal core security coverage |
Drupal 11.4.0 ended security support for 11.2.x and 10.5.x. Drupal 10 itself is scheduled to reach end of life in December 2026 when Drupal 12 is released.
If you do not know which branch your site runs, first check your Drupal version before using a vulnerability statistic to judge whether the site is actually exposed.
What Do Drupal Vulnerability Statistics Actually Tell Us?
The data supports several conclusions, but it does not support simplistic claims such as “Drupal is secure because it has fewer CVEs” or “Drupal is insecure because it has many contributed-module advisories.”
The statistics describe the ecosystem, not your installation. A site scanner is what turns ecosystem data into a list of findings you can act on.
The strongest findings are:
- Drupal core produces relatively few advisories each year compared with the contributed-project ecosystem.
- Contributed-project advisories dominate Drupal’s official historical security-advisory dataset.
- Most Drupal core advisories in 2026 are Moderately Critical.
- XSS is the most frequent vulnerability label among 2026 core advisories.
- A small number of severe vulnerabilities account for much of Drupal’s exploitation history.
- Confirmed exploitation can change the priority of a vulnerability very quickly, as CVE-2026-9082 demonstrated.
- End-of-life software creates a different risk from a supported branch because regular security fixes are no longer provided.
What the statistics do not tell you is whether a particular Drupal website is secure.
A real site can also contain:
- vulnerable contributed modules
- unsupported modules
- custom modules and themes
- misconfigured permissions
- exposed services
- outdated PHP or server dependencies
- weak authentication or access controls
For that broader question, see our analysis of whether Drupal is secure.
What Should Drupal Site Owners Do With These Statistics?
The practical lesson is not to panic every time the annual vulnerability count rises. The better response is to identify which disclosures apply to your actual stack and prioritize those with meaningful exploitability or exposure.
For Drupal administrators:
- stay on a currently supported Drupal branch
- inventory every contributed module and theme
- remove unsupported or unnecessary projects
- monitor Drupal Security Team advisories
- prioritize confirmed exploited vulnerabilities and high-impact anonymous attack paths
- verify remediation after patching
A continuous process is more useful than checking vulnerability statistics once per year. Our guide to continuous vulnerability scanning explains how to monitor changing exposure, while our guide to prioritizing vulnerability remediation covers how to move beyond severity scores alone.
Methodology and Sources
This report was updated in September 2026 and deliberately keeps several Drupal security datasets separate.
The methodology is:
- Official Drupal security advisories are the primary source for Drupal core advisory counts, advisory titles, Drupal risk ratings, and vulnerability classifications.
- Drupal Security Team’s annual track record is used for historical core-versus-contributed advisory counts.
- Drupal’s CVE assignment policy is used to explain why security-advisory counts and CVE counts can differ.
- CISA KEV is used to identify vulnerabilities with confirmed exploitation.
- W3Techs is used for current Drupal usage and CMS market-share context.
- Third-party vulnerability databases are used to show how database scope affects reported totals, not as substitutes for Drupal’s own advisory data.
Calculated percentages, including the 2026 severity distribution and contributed-project share, are derived from the published source counts. The 2026 Drupal Security Team track-record row is a year-to-date snapshot rather than a full-year figure, and contributed-project advisories have continued to be published since that snapshot.
HOW TO CITE THESE NUMBERSAlways preserve the source, date, and denominator. “12 Drupal core advisories in 2026” is different from “12 Drupal vulnerabilities,” and “6.7% of top-10,000 sites whose CMS is known” is different from “6.7% of the world’s top 10,000 websites.”
Frequently Asked Questions
How many Drupal vulnerabilities are there in 2026?
There is no single universal total because different datasets count different things. Drupal’s official records show 12 core security advisories in 2026, while its year-to-date security track-record table lists 73 contributed-project advisories. CVE databases can report different totals because not every advisory maps one-to-one to a CVE and different databases use different product scopes.
Why do Drupal vulnerability databases report different numbers?
Some databases count Drupal core only, while others include contributed modules, Drupal 7 projects, associated products, or records mapped to the Drupal vendor. Drupal’s own CVE assignment policy also means a security advisory does not necessarily correspond one-to-one with a CVE. Always check what the database is counting before comparing totals.
What is the most common Drupal core vulnerability type in 2026?
Cross-site scripting is the most frequent vulnerability label among Drupal’s 12 core advisories published in 2026. Four advisories, or 33.3%, are labeled as XSS issues. Gadget-chain advisories are second with two.
What severity are most Drupal vulnerabilities in 2026?
Among the 12 Drupal core advisories published in 2026, eight are rated Moderately Critical on Drupal’s 0-to-25 risk scale. Two are Critical, one is Highly Critical, and one is Less Critical.
What was the biggest Drupal vulnerability?
Drupalgeddon2, CVE-2018-7600, remains one of the most consequential Drupal vulnerabilities. It was an unauthenticated remote code execution flaw affecting multiple Drupal generations, was mass exploited, is listed in CISA’s Known Exploited Vulnerabilities catalog, and has been associated with ransomware campaigns. The original 2014 Drupalgeddon, CVE-2014-3704, was also notable because automated compromises began within hours of disclosure.
Is CVE-2026-9082 being exploited?
Yes. Drupal disclosed CVE-2026-9082 on May 20, 2026 and updated its advisory on May 22 after exploit attempts were detected in the wild. Drupal increased its risk score from the original 20/25 to 23/25, and the vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog.
Are most Drupal vulnerabilities in core or contributed modules?
In Drupal’s official security-advisory dataset, contributed projects account for far more advisories than Drupal core. For example, the official 2025 figures were 113 contributed-project advisories and eight core advisories. The current 2026 track-record snapshot lists 73 contributed and 12 core advisories.
How quickly are Drupal vulnerabilities exploited?
There is no single average for all Drupal vulnerabilities. Major incidents have ranged from less than seven hours for the original 2014 Drupalgeddon to about 14 days before documented automated exploitation of CVE-2018-7600, three days for CVE-2019-6340, and about two days for confirmed exploitation attempts against CVE-2026-9082.
Which Drupal versions still receive security updates?
As of September 2026, Drupal’s scheduled core security releases cover the 11.4.x, 11.3.x, and 10.6.x branches. Older minor branches have fallen out of regular security support, while Drupal 7, 8, and 9 are end-of-life. Drupal 10 is scheduled to reach end of life in December 2026.
Is Drupal secure?
Vulnerability counts alone cannot answer whether Drupal is secure. Drupal has a mature coordinated disclosure process and relatively few core advisories, but contributed modules, custom code, end-of-life versions, configuration, patch speed, and real-world exploitation all affect the security of an individual site.


