CVE-2015-6659: Drupal

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

Affected products

  • Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …

Published 2015-08-24. Last modified 2026-06-17.