← All CVEs NewScan detects
critical

CVE-2018-7600

Drupalgeddon2 - unauthenticated remote code execution via Form API render arrays

Severity
critical
Affected product
Drupal
Affected versions
Drupal < 7.58
Affected versions
Drupal ≥ 8.0.0, < 8.5.1
Fixed in
Drupal 7.58
Fixed in
Drupal 8.5.1
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Drupal from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

COMPONENT VERSION RANGE

NewScan fingerprints Drupal from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →