AI SEO Link Advisor - Less critical - Server-side Request Forgery - SA-CONTRIB-2025-095

Date: 
2025-August-06
CVE IDs: 
CVE-2025-8675

This module enables you to provide SEO analysis and recommendations for a given URL.

The module doesn't sufficiently sanitize user-supplied URLs, leading to a Server-side request forgery (SSRF) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access seo analyzer".

GoogleTag Manager - Moderately critical - Cross-site scripting - SA-CONTRIB-2025-094

Date: 
2025-July-30
CVE IDs: 
CVE-2025-8362

This module enables you to integrate Google Tag Manager (GTM) into your Drupal site by allowing administrators to configure and embed GTM container snippets.

The module doesn't sufficiently sanitize the GTM container ID under the scenario where a user with the Administer gtm permission enters malicious input into the GTM-ID field. This value is directly inserted into a <script> tag, making the site vulnerable to Cross-site Scripting (XSS) attacks.

Config Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-093

Date: 
2025-July-30
CVE IDs: 
CVE-2025-8361

This module enables you to access an edit page for a config page.

The module doesn't sufficiently check the access permissions (hook_ENTITY_TYPE_access() wasn't taken into account).

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit ID config page" and that it only affects sites that have access restricted via the hook_ENTITY_TYPE_access() hook.

COOKiES Consent Management - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-092

Date: 
2025-July-23
CVE IDs: 
CVE-2025-8092

This module allows you to manage video media items using the COOKiES module (disabling external video elements). These elements will be enabled again, once the COOKiES banner is accepted.

The module doesn't sufficiently check whether to convert "data-src" attributes to "src" when their value might contain malicious content under the scenario, that module specific classes are set on the HTML element.

Real-time SEO for Drupal - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-091

Date: 
2025-July-16
CVE IDs: 
CVE-2025-7716

This module enables you to analyze the content that you're authoring for a website. It shows you a preview of what a search result might look like.

The module doesn't sufficiently escape the metadata from content while rendering the preview, opening up the possibility of a XSS attack.

This vulnerability is mitigated by the fact that an attacker must be able to author content that is analyzed by the Real-Time SEO module.

Block Attributes - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-090

Date: 
2025-July-16
CVE IDs: 
CVE-2025-7715

This module allows you to define custom attributes for a block. You can specify an attribute name to be added to the block in a predefined format.

The module does not sufficiently validate the provided attributes, which makes it possible to insert JavaScript event attributes such as onmouseover, onkeyup, etc. These attributes can execute JavaScript code when the page is rendered, leading to cross-site scripting (XSS) vulnerabilities.

File Download - Moderately critical - Access bypass - SA-CONTRIB-2025-089

Date: 
2025-July-16
CVE IDs: 
CVE-2025-7717

The File Download enables you to allow users to download file and image entities directly using a custom field formatter. It also provides an optional submodule to count and display file downloads in Views, similar to how the core statistics module tracks content views.

The File Download module does not properly validate input when handling file access requests. This can allow users to bypass protections and access private files that should not be publicly available.

Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088

Date: 
2025-July-09
CVE IDs: 
CVE-2025-7393

This module enables users to login by email address with the minimal configurations.

The module included some protection against brute force attacks on the login form, however they were incomplete. An attacker could bypass the brute force protection allowing them to potentially gain access to an account.

Cookies Addons - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-087

Date: 
2025-July-09
CVE IDs: 
CVE-2025-7392

This module provides a format filter, which allows you to "disable" iframes (e.g. remove their src attribute) specified by the user. These elements will be enabled again, once the Cookies banner is accepted.

The module doesn't sufficiently filter user-supplied content when their value might contain malicious content leading to a Cross-site Scripting (XSS) vulnerability.

Config Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086

Date: 
2025-July-02
CVE IDs: 
CVE-2025-7031

This module enables you to use config_pages as a content entity.

The module doesn't check permission or entity access before rendering config_pages content.

Pages

Subscribe with RSS Subscribe to Security advisories