CVE-2026-9082

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.


We have discovered 98,540 live websites that are affected by CVE-2026-9082.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains98,540 live websites (48% of Drupal install base)
Vulnerable Versions
  • from 8.9 through 10.4.10
  • from 10.5 through 10.5.10
  • from 10.6 through 10.6.9
  • from 11 through 11.1.10
  • from 11.2 through 11.2.12
  • from 11.3 through 11.3.10
Vulnerable Versions Count224 versions ( 66% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - May 20, 2026
  • Updated - May 23, 2026

Credits

  • Michael Maturi (michaelmaturi) (finder)
  • Björn Brala (bbrala) (remediation developer)
  • Benji Fisher (benjifisher) (remediation developer)
  • catch (catch) (remediation developer)
  • Lee Rowlands (larowlan) (remediation developer)
  • Dave Long (longwave) (remediation developer)
  • Drew Webber (mcdruid) (remediation developer)
  • Jess (xjm) (remediation developer)
  • Anna Kalata (akalata) (coordinator)
  • Benji Fisher (benjifisher) (coordinator)
  • catch (catch) (coordinator)
  • Damien McKenna (damienmckenna) (coordinator)
  • Neil Drumm (drumm) (coordinator)
  • Greg Knaddison (greggles) (coordinator)
  • Heine Deelstra (heine) (coordinator)
  • Tim Hestenes Lehnen (hestenet) (coordinator)
  • Dave Long (longwave) (coordinator)
  • Drew Webber (mcdruid) (coordinator)
  • Juraj Nemec (poker10) (coordinator)
  • Pierre Rudloff (prudloff) (coordinator)
  • Jess (xjm) (coordinator)
  • Cathy Theys (yesct) (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-9082
United States37,264 websites



Germany8,938 websites
France7,529 websites
Belgium4,914 websites
GB3,710 websites
Netherlands3,383 websites
Canada2,528 websites
Russia2,474 websites
Switzerland2,424 websites
Italy2,159 websites

Website Distribution by TLD

Number of websites using CVE-2026-9082
.com25,324 websites
.org9,918 websites
.edu6,833 websites
.de5,989 websites
.be4,876 websites
.fr4,255 websites
.nl3,081 websites
.ca2,076 websites
.ch2,040 websites
.ru1,948 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-9082

Top websites that are affected by CVE-2026-9082. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk GB***
*********.com United States***
***.gov United States***
***.gov United States*,***
*******.gov United States*,***
***.gov United States*,***
***.gov United States*,***
******.com United States*,***
*******.com United States*,***
***.org United States*,***
See full domain list

FAQ

CVE-2026-9082 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Drupal
A total of 98,540 websites have been identified as vulnerable to CVE-2026-9082, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2026-9082 vulnerability.
Drupal versions up to 11.3.10 are vulnerable to CVE-2026-9082.
CVE-2026-9082 is resolved in version 11.3.10 of Drupal.