Show advisories for only Drupal core, only PSAs, or all security advisories

Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by community members.

Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089

Date: 
2026-July-22
CVE IDs: 
CVE-2026-15088

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16645

The Photoswipe Drupal module provides integration for the widely used PhotoSwipe lightbox library to display / zoom images in lightbox galleries using the provided image formatters.

The module didn't sufficiently check access permissions, when viewing an image using the photoswipe image gallery display formatter, in versions < 3.0.4 (Drupal 8) or < 3.2.0 (Drupal 9 / Drupal 10).

Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16644

This module enables you to retrieve and submit webform submissions via REST endpoints.

The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16643

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16642

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16641

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16646

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16640

This module enables you to add autocomplete suggestions for search forms created with the Search API module.

The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.

Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16639

In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.

The module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.

This vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.

Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16638

This module provides a better UI for managing and selecting Media entities in a folder structure.

The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.

Pages

Subscribe with RSS Subscribe to Security advisories for contributed projects