CVE-2025-31674

Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.


We have discovered 108,654 live websites that are affected by CVE-2025-31674.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains108,654 live websites (51% of Drupal install base)
Vulnerable Versions
  • from 8 through 10.3.13
  • from 10.4 through 10.4.3
  • from 11 through 11.0.12
  • from 11.1 through 11.1.3
Vulnerable Versions Count262 versions ( 83% of all versions)


Common Weakness Enumeration

CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes



Details

  • Published - Mar 31, 2025
  • Updated - Apr 3, 2025

Credits

  • anzuukino (finder)
  • shin24 (finder)
  • ghost of drupal past (remediation developer)
  • Dave Long (longwave) (remediation developer)
  • Drew Webber (mcdruid) (remediation developer)
  • nicxvan (remediation developer)
  • shin24 (remediation developer)

Website Distribution by Country

Number of websites using CVE-2025-31674
United States39,198 websites



Germany10,305 websites
France8,282 websites
Belgium5,208 websites
GB3,856 websites
Netherlands3,686 websites
Russia3,245 websites
Canada2,950 websites
Italy2,761 websites
Switzerland2,440 websites

Website Distribution by TLD

Number of websites using CVE-2025-31674
.com29,210 websites
.org10,570 websites
.edu6,730 websites
.de6,630 websites
.be4,917 websites
.fr4,598 websites
.nl3,299 websites
.ru2,586 websites
.it2,159 websites
.ca2,158 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-31674

Top websites that are affected by CVE-2025-31674. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk GB***
*********.com United States***
***.gov United States***
*******.gov United States*,***
***.gov United States*,***
***.gov United States*,***
******.com United States*,***
*****.com United States*,***
*******.com United States*,***
***.*******.edu United States*,***
See full domain list

FAQ

CVE-2025-31674 is Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal
A total of 108,654 websites have been identified as vulnerable to CVE-2025-31674, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2025-31674 vulnerability.
Drupal versions up to 11.1.3 are vulnerable to CVE-2025-31674.
CVE-2025-31674 is resolved in version 11.1.3 of Drupal.