CVE-2026-9082
KEV Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 84.6%
- 100th pct
- KEV
- Listed
- 2026-05-22
- Class
- oss containerizable
- CWE-89
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
Affected packages
| Bitnami | drupal | 10.5.0 → 10.5.10 |
| Bitnami | drupal | 10.6.0 → 10.6.9 |
| Bitnami | drupal | 11.0.0 → 11.1.10 |
| Bitnami | drupal | 11.2.0 → 11.2.12 |
| Bitnami | drupal | 11.3.0 → 11.3.10 |
| Bitnami | drupal | 8.9.0 → 10.4.10 |
| Packagist | drupal/core | 10.5.0 → 10.5.10 |
| Packagist | drupal/core | 10.6.0 → 10.6.9 |
| Packagist | drupal/core | 11.0.0 → 11.1.10 |
| Packagist | drupal/core | 11.2.0 → 11.2.12 |
| Packagist | drupal/core | 11.3.0 → 11.3.10 |
| Packagist | drupal/core | 8.9.0 → 10.4.10 |
References
Status: profiled · ingested 2026-07-23T18:00:18.000Z