Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.
We have discovered 108,654 live websites that are affected by CVE-2025-31674.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 108,654 live websites (51% of Drupal install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 262 versions ( 83% of all versions) |
| 39,198 websites | |
| 10,305 websites | |
| 8,282 websites | |
| 5,208 websites | |
| 3,856 websites | |
| 3,686 websites | |
| 3,245 websites | |
| 2,950 websites | |
| 2,761 websites | |
| 2,440 websites |
| .com | 29,210 websites |
| .org | 10,570 websites |
| .edu | 6,730 websites |
| .de | 6,630 websites |
| .be | 4,917 websites |
| .fr | 4,598 websites |
| .nl | 3,299 websites |
| .ru | 2,586 websites |
| .it | 2,159 websites |
| .ca | 2,158 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.**.uk | *** | ||
| *********.com | *** | ||
| ***.gov | *** | ||
| *******.gov | *,*** | ||
| ***.gov | *,*** | ||
| ***.gov | *,*** | ||
| ******.com | *,*** | ||
| *****.com | *,*** | ||
| *******.com | *,*** | ||
| ***.*******.edu | *,*** |
FAQ