Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by a community member. These posts by the Drupal security team are also sent to the security announcements e-mail list.

Metatag -Moderately Critical - Information disclosure - SA-CONTRIB-2017-019

RESTful - Moderately Critical - Access Bypass - SA-CONTRIB-2017-018

Flag clear - Moderately Critical - Cross Site Request Forgery (CSRF) - SA-CONTRIB-2017-017

Search API Sorts - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-016

Hotjar - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-015

OSF for Drupal - Less Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-014

Acquia Content Hub - Moderately Critical - Access Bypass - SA-CONTRIB-2017-013

Wetkit Omega - Moderately Critical - Access Bypass - SA-CONTRIB-2017-012

Facebook Pull - Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2017-011


Subscribe with RSS Subscribe to Security advisories for contributed projects