A flaw found in the Drupal core could allow a potential hacker under certain circumstances to bypass security restrictions by forging the password reset URLs. The vulnerability is considered as moderately critical in which an attacker can remotely trick a registered user of Drupal based website, such as an administrator, into launching a maliciously crafted URL in an attempt to take control of the target server. Drupal is used to power over 1 billion websites on the Internet, which puts Drupal in third place behind WordPress and Joomla.
Source: https://thehackernews.com/2015/03/hacking-drupal-website.html

