GHSA-ghwc-95x2-682j · Severity: medium — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
Conclusion & alert: CVE-2026-9082 is rated Active Exploitation (79/100): CVSS Medium severity, with high exploitation likelihood (EPSS 13.03%, 94th percentile). Core evidence: CISA KEV confirms active exploitation (added 2026-05-22) affecting Drupal / Core. SQL injection (CWE-89) Unauthenticated remote administrative access may be possible. Mandatory action: Assess exposure and apply mitigations immediately; prioritize emergency patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 52608 | exploit_db | edb | 2026-06-01 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-02 | 34.65% | 13.03% | -21.62% |
| 2 | 2026-05-31 | 34.17% | 34.65% | +0.48% |
| 3 | 2026-05-27 | — | 34.17% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-ghwc-95x2-682j · Severity: medium — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||