Drupal is designed with security in mind through secure APIs and features to prevent common issues like XSS and CSRF attacks. However, open source software can still be vulnerable if not configured securely, with 67% of major websites having XSS issues. While Drupal core and major contributed modules receive security support, users are responsible for securely configuring permissions and input formats. The volunteer Drupal security team works to ensure the best security for Drupal and contributed modules through design, education and fixing vulnerabilities.