CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-113

Date: 
2025-October-22
CVE IDs: 
CVE-2025-12083

CivicTheme is a design system and theme framework used to build content-rich Drupal websites. It includes editorial workflows, structured content types, and flexible theming components.

CivicTheme does not sufficiently filter field data before rendering them in Twig templates. This combined with multiple instances of the Twig raw filter throughout CivicTheme components, allows for the injection of malicious scripts in browser contexts.

CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025-112

Date: 
2025-October-22
CVE IDs: 
CVE-2025-12082

CivicTheme is a design system and theme framework used to build content-rich Drupal websites. It includes editorial workflows, structured content types, and flexible theming components.

The theme doesn't sufficiently check access to entities when they are displayed as reference cards used in manual lists, which leads to an information disclosure vulnerability

Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10929

This module allows you to specify an HTTP header name to determine the client's IP address.

The module doesn't sufficiently handle all cases under the scenario if Drupal Core settings $settings['reverse_proxy'] is set to TRUE and $settings['reverse_proxy_addresses'] is configured.

This vulnerability allows an attacker to spoof a request IP address (as Drupal sees it), potentially bypassing a variety of controls.

Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10930

This module allows you to use different currencies on your website and do currency conversion.

The module doesn't sufficiently protect routes used to enable and disable currencies from Cross-Site Request Forgery (CSRF) attacks, potentially allowing an attacker to trick an admin into changing settings.

Umami Analytics - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-109

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10931

This module enables you to add Umami Analytics web statistics tracking system to your website.

The "administer umami analytics" permission allows inserting an arbitrary JavaScript file on every page. While this is an expected feature, the permission lacks the "restrict access" flag, which should alert administrators that this permission is potentially dangerous and can lead to cross-site scripting (XSS) vulnerabilities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer umami analytics”.

Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10928

This module enables users to sign in with an access code instead of entering user names and passwords. When users are allowed to pick their own access codes, they can guess other users' access codes based on the fact that access codes need to be unique and the system warns if the code of their choice is taken.

This vulnerability is mitigated by the fact that an attacker must have a role with the "change own access code" permission.

Plausible tracking - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-107

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10927

This module integrates Plausible Analytics on a site.

The module did not properly filter output in certain cases.

This vulnerability is mitigated by the fact that an attacker must have permission to add raw HTML to the website, such as an unfiltered WYSIWYG field on a public-facing comment.

JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10926

This module enables you to store and display JSON data using optional 3rd party libraries.

The module doesn't sufficiently filter data using some of the included field formatters leading to a Cross-site Scripting (XSS) vulnerability.

Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105

Date: 
2025-September-03
CVE IDs: 
CVE-2025-9954

This module enables you to connect a Drupal site to the Acquia DAM service, which syncs media from the third party service to the site.

The module doesn't sufficiently validate authorization to a list of DAM assets currently synced to the website creating an access bypass vulnerability.

This vulnerability is mitigated by the fact that it only impacts sites where users having the “view media” permission accessing any DAM asset is undesirable.

Pages

Subscribe with RSS Subscribe to Security advisories