# Drupal

Drupal (drupal.org): subprocessors, data processing agreement, security documents and changes, as monitored by Third Party Index.

- Page: https://thirdpartyindex.com/vendors/drupal
- Documents last verified: 2026-10-07
- Transparency rating: 21/100 (how much it publishes, not how secure it is): Subprocessor list 0/30 (not found); Processing locations 0/8 (no list); Purposes 0/7 (no list); Data processing addendum 0/12 (not found); Trust center 8/8; Privacy policy 0/6 (not found); security.txt 0/6 (not found); Security page 5/5; Status page 0/5 (not found); Vulnerability disclosure 0/5 (not found); Pages still reachable 8/8
- Cite as: Drupal, Third Party Index, https://thirdpartyindex.com/vendors/drupal (data CC BY 4.0)

## Documents

| Document | URL | Last verified | Last changed |
|---|---|---|---|
| Trust center | https://www.drupal.org/trust | 2026-10-07 | 2026-09-27 |
| Security page (currently unreachable) | https://www.drupal.org/security | 2026-10-05 | 2026-10-05 |

## Subprocessors (0)

No subprocessor list has been found or read for this vendor.

## Subprocessor of (0)

No tracked vendor lists it.

## Security record

CISA's Known Exploited Vulnerabilities catalog lists 5 vulnerabilities in its software:

- CVE-2026-9082 (Core), listed 2026-05-22: Drupal Core SQL Injection Vulnerability
- CVE-2018-7602 (Core), listed 2022-04-13: Drupal Core Remote Code Execution Vulnerability (known ransomware use)
- CVE-2019-6340 (Core), listed 2022-03-25: Drupal Core Remote Code Execution Vulnerability
- CVE-2020-13671 (Drupal core), listed 2022-01-18: Drupal core Un-restricted Upload of File
- CVE-2018-7600 (Drupal Core), listed 2021-11-03: Drupal Core Remote Code Execution Vulnerability (known ransomware use)

---

Third Party Index (https://thirdpartyindex.com) monitors vendors' public security and privacy documents and keeps each version as evidence. Data CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/); vendors' own documents are theirs. API: https://thirdpartyindex.com/api
