cvss9.8
how bad it is if exploited, out of 10
epss90.0%
chance of exploitation in the next 30 days
xyz score7.3
CyberXYZ composite, and a working exploit is published
fig. 01 — GHSA-ghwc-95x2-682j, the advisory selected below
GHSA-ghwc-95x2-682j
CRITICALCVE-2026-9082Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
- Affected
- >=8.9.0, <10.4.10, >=10.5.0, <10.5.10, >=10.6.0, <10.6.9, >=11.0.0, <11.1.10, >=11.2.0, <11.2.12, >=11.3.0, <11.3.10
- Fixed in
- 10.4.10
- Weakness
- CWE-89
- Published
- 2026-05-20
- Source
- github
GHSANVDMITRE
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so packagist packages are not covered.
Checked 2026-09-22 at 00:40 UTC. The most recent advisory here was published 2026-05-20. Updated continuously from NVD, GHSA, OSV and CNA feeds.