critical
CVE-2018-7600
Drupalgeddon2 - unauthenticated remote code execution via Form API render arrays
- Severity
- critical
- Affected product
- Drupal
- Affected versions
- Drupal < 7.58
- Affected versions
- Drupal ≥ 8.0.0, < 8.5.1
- Fixed in
- Drupal 7.58
- Fixed in
- Drupal 8.5.1
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Drupal from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
COMPONENT VERSION RANGE
NewScan fingerprints Drupal from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →