CVE-2018-7600
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.99% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-20
- Published
- 2018-03-29
- Updated
- 2025-10-21
Proof-of-concept exploits (60)
- https://research.checkpoint.com/uncovering-drupalgeddon-2/
- 0xAJ2K/CVE-2018-76001★ · 2021-06-05
- Dowonkwon/drupal-cve-2018-7600-poc0★ · 2025-04-27
- FireFart/CVE-2018-760071★ · 2018-04-18
- M-Abid34/CVE-2018-76000★ · 2025-09-26
- MrR0b0t19/Easy-JPT3★ · 2025-06-02
- MrR0b0t19/Easy-JTP3★ · 2025-06-02
- SecPentester/CVE-7600-20184★ · 2018-10-21
- Sh4dowX404Unknown/Drupalgeddon20★ · 2024-02-03
- SyedGhufranRaza/CVE-2018-7600-Remote-Code-Execution0★ · 2025-08-20
- UltramanGaia/POC-EXP0★ · 2020-04-09
- amitnandi04/Common-Vulnerability-Exposure-CVE-0★ · 2020-10-14
- anldori/CVE-2018-76000★ · 2022-07-29
- cved-sources/cve-2018-76000★ · 2021-04-15
- daynis-olman/drupalgeddon-shell-exploit1★ · 2023-02-15
- dr-iman/CVE-2018-7600-Drupal-0day-RCE7★ · 2018-04-14
- dreadlocked/Drupalgeddon2601★ · 2021-01-08
- drugeddon/drupal-exploit1★ · 2019-03-24
- dwisiswant0/CVE-2018-76004★ · 2018-04-14
- emzkie2018/S4nji1-Drupalgeddon20★ · 2018-09-28
- happynote3966/CVE-2018-76000★ · 2018-07-17
- jirojo2/drupalgeddon25★ · 2018-04-14
- jyo-zi/CVE-2018-76000★ · 2018-05-25
- kato83/poc-vulnerability-advisor0★ · 2025-09-18
- knqyf263/CVE-2018-76003★ · 2018-11-17
- lorddemon/drupalgeddon211★ · 2018-04-19
- mr-won/CVE-2018-7600.0★ · 2025-03-19
- muhammedkayag/CVE-2018-76001★ · 2026-06-19
- ncinfinity69/asulo0★ · 2018-11-04
- nika0x38/CVE-2018-76000★ · 2025-09-21
- pimps/CVE-2018-7600141★ · 2018-04-26
- qiantu88/test0★ · 2018-12-19
- r0lh/CVE-2018-76000★ · 2023-01-17
- r3dxpl0it/CVE-2018-76009★ · 2020-08-31
- rabbitmask/CVE-2018-7600-Drupal78★ · 2020-04-15
- rafaelcaria/drupalgeddon2-CVE-2018-76000★ · 2021-10-27
- rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution0★ · 2025-08-08
- raytran54/CVE-2018-76000★ · 2024-07-17
- ret2x-tools/drupalgeddon2-rce0★ · 2023-12-26
- ruthvikvegunta/Drupalgeddon20★ · 2020-08-13
- shellord/CVE-2018-7600-Drupal-RCE4★ · 2019-10-17
- sl4cky/CVE-2018-76004★ · 2018-04-15
- sl4cky/CVE-2018-7600-Masschecker3★ · 2018-04-15
- soch4n/CVE-2018-76000★ · 2018-05-25
- thehappydinoa/CVE-2018-76007★ · 2023-07-18
- tpdlshdmlrkfmcla/CVE-2018-7600.0★ · 2025-03-19
- user20252228/CVE-2018-7600.0★ · 2025-03-19
- vphnguyen/ANM_CVE-2018-76000★ · 2021-11-26
- xxxTectationxxx/CVE-2018-76000★ · 2025-08-12
- ynsmroztas/drupalhunter0★ · 2020-06-18
- zhzyker/CVE-2018-7600-Drupal-POC-EXP8★ · 2020-04-07
- 4l13n-DN/POC-CVE-2018-7600
- Dungsocool/CVE-2018-7600
- RB4C/drupalgeddon2-CVE-2018-7600
- Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
- elkhaoudari/CVE-2018-7600-PoC
- erman-bolukbasi/web-penetration-drupal
- nayem-m/drupalgeddon2-cli
- a2u/CVE-2018-7600354★ · 2019-03-29
- g0rx/CVE-2018-7600-Drupal-RCE114★ · 2018-04-18
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/44482
- https://www.exploit-db.com/exploits/44449
- https://www.exploit-db.com/exploits/44448
Vulhub environments (1)
Exploit collections (3)
- chaitin/xray/blob/master/pocs/drupal-cve-2018-7600-rce.yml
- helloexp/0day/tree/master/100-%E5%90%84%E7%A7%8DCMS/Drupal/Drupal_CVE-2018-7600_v8.5.0
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2018/CVE-2018-7600.yaml