What happened
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
Affected versions
Drupal Core: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 44482Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)José Ignacio Rojo2018-04-17VerifiedExploit-DB 44449Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code ExecutionHans Topo & g0tmi1k2018-04-13VerifiedExploit-DB 44448Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)Vitalii Rudnykh2018-04-13VerifiedPoC-in-GitHub · g0rx/CVE-2018-7600-Drupal-RCECVE-2018-7600 Drupal RCE★ 114g0rx2018-03-30CandidatePoC-in-GitHub · a2u/CVE-2018-7600💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002★ 354a2u2018-03-30CandidatePoC-in-GitHub · dreadlocked/Drupalgeddon2Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)★ 603dreadlocked2018-04-12CandidatePoC-in-GitHub · knqyf263/CVE-2018-7600CVE-2018-7600 (Drupal)★ 3knqyf2632018-04-13CandidatePoC-in-GitHub · dr-iman/CVE-2018-7600-Drupal-0day-RCEDrupal 0day Remote PHP Code Execution (Perl)★ 7dr-iman2018-04-14CandidatePoC-in-GitHub · jirojo2/drupalgeddon2MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)★ 5jirojo22018-04-14CandidatePoC-in-GitHub · dwisiswant0/CVE-2018-7600PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).★ 4dwisiswant02018-04-14CandidatePoC-in-GitHub · thehappydinoa/CVE-2018-7600Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002★ 7thehappydinoa2018-04-15CandidatePoC-in-GitHub · sl4cky/CVE-2018-7600Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)★ 4sl4cky2018-04-15CandidatePoC-in-GitHub · sl4cky/CVE-2018-7600-MasscheckerTool to check for CVE-2018-7600 vulnerability on several URLS★ 3sl4cky2018-04-15CandidatePoC-in-GitHub · firefart/CVE-2018-7600CVE-2018-7600 - Drupal 7.x RCE★ 71firefart2018-04-16CandidatePoC-in-GitHub · pimps/CVE-2018-7600Exploit for Drupal 7 <= 7.57 CVE-2018-7600★ 140pimps2018-04-17CandidatePoC-in-GitHub · lorddemon/drupalgeddon2Exploit for CVE-2018-7600.. called drupalgeddon2,★ 11lorddemon2018-04-19CandidatePoC-in-GitHub · Hestat/drupal-checkTool to dive Apache logs for evidence of exploitation of CVE-2018-7600★ 2Hestat2018-04-24CandidatePoC-in-GitHub · Damian972/drupalgeddon-2Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)★ 1Damian9722018-05-01CandidatePoC-in-GitHub · soch4n/CVE-2018-7600★ 0soch4n2018-05-25CandidatePoC-in-GitHub · happynote3966/CVE-2018-7600★ 0happynote39662018-07-12CandidatePoC-in-GitHub · shellord/CVE-2018-7600-Drupal-RCEMASS Exploiter★ 4shellord2018-10-02CandidatePoC-in-GitHub · r3dxpl0it/CVE-2018-7600CVE-2018-7600 POC (Drupal RCE)★ 9r3dxpl0it2018-10-23CandidatePoC-in-GitHub · cved-sources/cve-2018-7600cve-2018-7600★ 0cved-sources2019-01-06CandidatePoC-in-GitHub · madneal/codeql-scannerThe exploit python script for CVE-2018-7600★ 0madneal2019-03-15CandidatePoC-in-GitHub · drugeddon/drupal-exploitCVE-2018-7600★ 1drugeddon2019-03-24CandidatePoC-in-GitHub · shellord/Drupalgeddon-Mass-ExploiterCVE-2018-7600 and CVE-2018-7602 Mass Exploiter★ 1shellord2019-10-10CandidatePoC-in-GitHub · zhzyker/CVE-2018-7600-Drupal-POC-EXPCVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本★ 8zhzyker2020-04-07CandidatePoC-in-GitHub · rabbitmask/CVE-2018-7600-Drupal7CVE-2018-7600【Drupal7】批量扫描工具。★ 8rabbitmask2020-04-12CandidatePoC-in-GitHub · ynsmroztas/drupalhunterCVE-2018-7600 0-Day Exploit (cyber-warrior.org)★ 0ynsmroztas2020-06-18CandidatePoC-in-GitHub · ruthvikvegunta/Drupalgeddon2CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE★ 0ruthvikvegunta2020-08-10CandidatePoC-in-GitHub · ludy-dev/drupal8-REST-RCE(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE★ 4ludy-dev2020-08-31CandidatePoC-in-GitHub · 0xAJ2K/CVE-2018-7600Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.★ 10xAJ2K2021-06-05CandidatePoC-in-GitHub · RB4C/drupalgeddon2-CVE-2018-7600★ 0RB4C2021-10-27CandidatePoC-in-GitHub · vphnguyen/ANM_CVE-2018-7600Detect with python and tracking IP★ 0vphnguyen2021-11-26CandidatePoC-in-GitHub · anldori/CVE-2018-7600★ 0anldori2022-04-25CandidatePoC-in-GitHub · r0lh/CVE-2018-7600Drupal CVE-2018-7600 RCE Pseudo-Shell PoC★ 0r0lh2022-12-17CandidatePoC-in-GitHub · raytran54/CVE-2018-7600★ 0raytran542024-06-12CandidatePoC-in-GitHub · tpdlshdmlrkfmcla/CVE-2018-7600.CVE-2018-7600.★ 0tpdlshdmlrkfmcla2025-03-19CandidatePoC-in-GitHub · Dowonkwon/drupal-cve-2018-7600-poc★ 0Dowonkwon2025-04-27CandidatePoC-in-GitHub · M-Abid34/CVE-2018-7600For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose★ 0M-Abid342025-08-04CandidatePoC-in-GitHub · rajaabdullahnasir/CVE-2018-7600-Remote-Code-ExecutionThis repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.★ 0rajaabdullahnasir2025-08-08CandidatePoC-in-GitHub · xxxTectationxxx/CVE-2018-7600Program python untuk melakukan RCE pada drupal versi 7.56★ 0xxxTectationxxx2025-08-12CandidatePoC-in-GitHub · muhammedkayag/CVE-2018-7600PoC of CVE-2018-7600★ 1muhammedkayag2025-08-12CandidatePoC-in-GitHub · SyedGhufranRaza/CVE-2018-7600-Remote-Code-ExecutionThis repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical vulnerability in Drupal 7 and 8 core enables remote code execution (RCE), and the PoC demonstrates its exploitation in a clear and educational manner.★ 0SyedGhufranRaza2025-08-20CandidatePoC-in-GitHub · nika0x38/CVE-2018-7600A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)★ 0nika0x382025-09-21CandidatePoC-in-GitHub · tea-celikik/Drupal-Exploit-LabDemonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)★ 0tea-celikik2025-09-24CandidatePoC-in-GitHub · 4l13n-DN/POC-CVE-2018-7600Drupal vulnerable a CVE-2018-7600★ 14l13n-DN2025-12-08CandidatePoC-in-GitHub · bixiPRO/Drupalgeddon2-CVE-2018-7600★ 0bixiPRO2026-02-10CandidatePoC-in-GitHub · Meraj1312/cve-2018-7600-drupalgeddon2-labEducational lab demonstrating CVE-2018-7600 (Drupalgeddon2) Remote Code Execution using a Docker-based vulnerable Drupal 7.56 environment.★ 1Meraj13122026-03-12CandidatePoC-in-GitHub · erman-bolukbasi/web-penetration-drupalPenetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec★ 0erman-bolukbasi2026-03-26CandidatePoC-in-GitHub · Dungsocool/CVE-2018-7600★ 0Dungsocool2026-05-30CandidatePoC-in-GitHub · nayem-m/drupalgeddon2-cliCLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education★ 0nayem-m2026-06-10CandidatePoC-in-GitHub · Prapul1/VulnHub-DC1-WriteupVulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password hash, and escalating to root via SUID find.★ 1Prapul12026-06-25CandidatePoC-in-GitHub · Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE★ 0Shams-Ul-Mehmood2026-08-06CandidatePoC-in-GitHub · elkhaoudari/CVE-2018-7600-PoC★ 1elkhaoudari2026-08-20CandidatePoC-in-GitHub · Vaibhav91one/drupalgeddon2-cve-labDrupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab★ 0Vaibhav91one2026-08-30CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.