VDB

GCVE-110-NCSC-2026-166

GCVE-110-NCSC-2026-166
Advisory PublishedCVSS 6.5/10
Vulnetix · Advisory published May 21, 2026
Drupal core versions 8.9.0 through certain 10.x and 11.x releases contain a SQL Injection vulnerability in the database abstraction API affecting PostgreSQL, alongside security fixes for Symfony and Twig dependencies.

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Risk Scores

CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
Drupalvers:unknown/*

References

advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›