Component blocks - Moderately critical - Cross site scripting - SA-CONTRIB-2026-123

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84915

This module enables you use UI Patterns with blocks, for use in Layout Builder.

The module doesn't sufficiently validate user input before passing to token replacement.

This vulnerability is mitigated by the fact that an attacker must have a role with the ability to edit layout builder layouts.

Calculate Working Days - Critical - Access bypass - SA-CONTRIB-2026-122

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84914

Calculate Working Days allows you to calculate working days
between 2 dates.

This module doesn't sufficiently restrict access to its settings form.

AI translate - Moderately critical - Access Bypass - SA-CONTRIB-2026-121

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84913

This module enables you to automatically translate entities.

The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities

AI (Artificial Intelligence) - Moderately critical - Access Bypass - SA-CONTRIB-2026-120

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84912

This submodule AI Translate enables you to automatically translate entities.

The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities

AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84911

This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website.

The module doesn't sufficiently sanitize for cross site scripting (XSS) when using the structured results using legacy agent setups.

This vulnerability is mitigated by the fact that an attacker must be able to invoke a prompt injection set via editorial content and the site must have been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon configuration. Any configuration setup or updated after these minor versions are not affected.

Advanced Search - Moderately critical - Access bypass - SA-CONTRIB-2026-118

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84910

This module enables AJAX updates for advanced search, facet, and search result blocks.

The module doesn’t sufficiently check block access when arbitrary block IDs are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.

This vulnerability is mitigated by the fact that an attacker must know or guess a restricted block’s machine ID, and the block must contain sensitive content protected by block access or visibility restrictions.

Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81160

Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.

Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.

Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.

Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81201

This module enables you to create one or more multisites with highly granular page permissions.

The module doesn't sufficiently sanitize HTML code contained in the page name when displayed in the built-in tree browser. This results in a cross-site scripting vulnerability that may allow attackers to execute arbitrary JavaScript in the context of the user’s session.

This vulnerability is mitigated by the fact that an attacker must have the ability to create pages whose page title supports HTML.

LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81205

This module enables users to authenticate using LDAP or Active Directory credentials.

The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.

Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81164

The Entity PDF module can create a PDF from any entity based on any View mode.

This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.

Pages

Subscribe with RSS Subscribe to Security advisories