Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by a community member. These posts by the Drupal security team are also sent to the security announcements e-mail list.

DownloadFile - Critical - Unsupported - SA-CONTRIB-2017-023

Unpublished 404 - Critical - Unsupported - SA-CONTRIB-2017-021

Views - Moderately Critical - Access Bypass - SA-CONTRIB-2017-022

Timezone Detect - Moderately Critical - Cross Site Request Forgery - SA-CONTRIB-2017-020

Metatag -Moderately Critical - Information disclosure - SA-CONTRIB-2017-019

RESTful - Moderately Critical - Access Bypass - SA-CONTRIB-2017-018

Flag clear - Moderately Critical - Cross Site Request Forgery (CSRF) - SA-CONTRIB-2017-017

Search API Sorts - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-016

Hotjar - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-015

OSF for Drupal - Less Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-014

Pages

Subscribe with RSS Subscribe to Security advisories for contributed projects