Show advisories for only Drupal core, only PSAs, or all security advisories

Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by community members.

Webform Submissions Delete - Moderately critical - Access bypass - SA-CONTRIB-2026-133

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84921

This module enables you to delete Webform submissions in bulk using a specified date range.

The module doesn't sufficiently restrict access to the delete form.

A separate PHP fatal error issue may prevent exploitation in practice on Drupal 10+.

Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84920

This module creates permissions per node content type to control access to unpublished content.

The module has allowed view access for published content, overriding other access mechanisms that might have been in place.

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-131

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84919

This module enables you to add dynamic caption support to PhotoSwipe image galleries.

The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.

Monobank payment API - Moderately critical - Access bypass - SA-CONTRIB-2026-130

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84918

The Monobank payment API module provides integration with Monobank acquiring payments.

The module did not verify the Monobank webhook signature before processing payment status callbacks.

Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129

Date: 
2026-September-02
CVE IDs: 
CVE-2026-81163

A module to import media files into media library.

The import folder is a plain textfield with no validation. Point it at any directory the web user can read, and the importer copies every file whose extension matches a selected media type into the public files directory and publishes it as a Media entity. Files that were deliberately kept outside the webroot, such as a private file store, become downloadable by anonymous visitors at a predictable URL.

Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128

Date: 
2026-September-02
CVE IDs: 
CVE-2026-16648

This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports > Mail log.

The module doesn't sufficiently redact the content of the emails it logs. Account related emails are stored with their one-time login links intact, so any user who can view the log can obtain a one-time login link for any account, including user 1, and use it to log in as that account.

Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84917

This module enables you to restrict access to JSON:API routes based on specific user roles.

The module doesn't sufficiently enforce access controls under scenarios where a request mimics an XMLHttpRequest.

Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84916

This islandora_advanced_search sub module enables AJAX updates for advanced search, facet, and search result blocks.

The module doesn't sufficiently check block access when arbitrary block ID's are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.

Email Verification / SMS Verification / OTP Verification - Critical - Cross Site Scripting - SA-CONTRIB-2026-125

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84924

This module enables you to add an extra layer of verification for user registration.

The module doesn't sufficiently filter user-supplied input before output, resulting in an unauthenticated reflected Cross-site Scripting (XSS) vulnerability.

Email Verification / SMS Verification / OTP Verification - Critical - Access Bypass - SA-CONTRIB-2026-124

Date: 
2026-September-02
CVE IDs: 
CVE-2026-84923

This module enables you to add extra layer of verification for user registration.

The module doesn't sufficiently validate user-supplied input resulting in an account takeover vulnerability.

Pages

Subscribe with RSS Subscribe to Security advisories for contributed projects