The 2018 Pwnie Nominee For Best Server-Side Bug

Drupalmageddon 2 and 3

Credit: Jasper Mattsson (two ts two sses!)

Why does it take 14 people on the Drupal core team to fix one bug, and not even correctly? Drupal and its insane sibling Joomla are responsible for running more websites than the Florida crab spider.Aside from Kink-shaming their own developers, Drupal is known for the incredible masochism of writing their entire framework in PHP. Luckily any server running Drupal is probably being managed by a coordinated group of crypto-miners now, which is part of their total value proposition.

Drupalmageddon 2 and 3 (CVE-2018-7602 CVE-2018-7600)