Drupal Association

Security Scorecard

Score

81C

Total CVEs

18

Patch Rate

78%

14 patched

Avg Response

56d

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical1
High3
Medium14
Low0

Patch Status

Patched14 (78%)
Partial/Workaround0 (0%)
Unpatched4 (22%)

CVEs (18)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14840Drupal HTTP Client Manager VulnerabilityHigh7.5-Patched
CVE-2025-13983Drupal Tagify XSSMedium5.4-Patched
CVE-2025-13982Drupal Login Time Restriction CSRFHigh8.11dUnpatched
CVE-2025-12848-Medium6.119dUnpatched
CVE-2025-12760-Medium5.427dPatched
CVE-2025-13081-Medium5.927dPatched
CVE-2025-13082-Medium4.327dPatched
CVE-2025-13080-Medium5.327dPatched
CVE-2025-10927-Medium6.150dPatched
CVE-2025-12083-Medium6.150dPatched