Advanced File System turns Drupal's file storage into a manageable, observable and maintainable subsystem.
The Advanced Filesystem: Backup submodule does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.
The vulnerability is mitigated by the fact that advanced_filesystem_backup module must be enabled.
This module enables you to restrict access to routes by IP address.
The module doesn't reliably restrict a subset of dynamic routes, leading to an access bypass vulnerability. The impact depends on how a site uses this module and whether it has any routes that are dynamic.
The Examples for Developers project aims to provide high-quality, well-documented API examples for a broad range of Drupal core functionality.
The "Email Example" feature implemented by the email_example submodule can be used to send illegitimate emails to arbitrary email addresses.
Therefore, the email_example sub-module is being removed from Examples for Developers until a version demonstrating security best practices can be added back in the future. Developers who based a new module on this example should review their code.
This module enables you to restrict view access to single nodes via taxonomy terms.
The module doesn't sufficiently check access rights when in "Permission mode" and a node referencing a deleted taxonomy term is accessed via JSON:API.
This vulnerability is mitigated by the fact that it requires a specific module configuration, references to a deleted term, and access via JSON:API to be present.
This module enables you to configure a WIKI-like input filter that allows users to create links to site and external content.
The module doesn’t sufficiently prevent page titles being viewed for certain privately-accessible URLs.
This vulnerability is mitigated by the fact that an attacker must have access to use a text format with the Freelinking plugin configured to allow privately-accessible external URLs to be crawled. Site administrators may want to disable this functionality to evaluate any risk.
This module enables you to show a breadcrumb trail for taxonomy term hierarchies.
The module doesn't sufficiently check for view access of parent terms before rendering the crumb segment.
This vulnerability is mitigated by the fact that the setting "Add parent hierarchy" (term_hierarchy) must be enabled, and at least one term has a term in the parent hierarchy that is unpublished.
The module Country provides a dedicated field type for Drupal core's official country list.
The module does not sufficiently escape user input in its autocomplete widget, which can lead to a cross site scripting vulnerability.
This vulnerability is mitigated by the fact that it can not occur out of the box with the Country module, additional module(s) or custom code is required.
This module adds a "Generate internal links" action to the AI CKEditor toolbar, letting editors select text and have the module search the site's content for relevant pages to link to.
The module's search query did not respect entity access when returning results to the browser.
This vulnerability is mitigated by the fact that an user must have permission to use the AI CKEditor "Generate internal links" feature on a text format.
The DKAN module enables organizations and individuals to build open data portals in Drupal. The DKAN datastore imports tabular data files into database tables and exposes them for querying with a JSON API.
The module does not correctly check access for all of its endpoints, leading to a potential access bypass.
The vulnerability is mitigated by the fact that it is only impactful for sites that do not give "access content" permission to the anonymous role.
This module enables you to add an extra layer of verification for user login flow.
The Two Factor Authentication - TFA / Passwordless Login module for Drupal contains a vulnerability in the headless login endpoint that can disclose the site's stored miniOrange customer API key to unauthenticated users.
The vulnerability is mitigated by the fact that Headless 2FA must be turned on by a user with a miniorange 2fa headless permission, which is a restricted permission.
This module enables you to audit a Drupal site by generating reports about its content, entities, display modes and configuration.
The module doesn't sufficiently check entity access when rendering an entity through the display-mode example route. This allows an attacker to view unpublished or otherwise access-restricted content.
This vulnerability is mitigated by the fact that field-level access is still enforced, so fields that are themselves access-restricted (for example a user's email or password hash) are not disclosed.
This module enables you to "share" a view display within another website via an iframe.
The module doesn't sufficiently block access to view displays. Although the views data is not displayed, resource-intensive views could still be executed which could affect site performance.
This vulnerability is mitigated by the fact that an attacker must know the view and display IDs.
The Leaflet module provides integration with the Leaflet JS mapping library.
Under certain circumstances, when the Leaflet field formatter builds a map it does not filter content titles, leading to a stored cross-site scripting vulnerability.
This vulnerability is mitigated by the fact an attacker needs to have permission to create or edit content that is used in a Leaflet map.
The Inline Formatter Field module allows site builders to template and style entities with a field.
This module does not properly protect against template injection when parsing, allowing users to render protected data or execute unsafe Twig commands.
This module enables you to link the output of a field to a URL or to the value of another field.
The module doesn't sufficiently separate field content from template code when rendering linked field output. Depending on the Twig extensions installed on the site, this can be used to expose site configuration values, which may include sensitive information such as API keys or credentials.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit content in a field that has Linked Field enabled in its display settings.
This module renders entity add/edit forms inside an AJAX dialog for use with entity reference fields.
This module relies only on the "access administration pages" permission, without checking whether the current user had create or update access to the entity itself.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access administration pages".
Actstream (short for Activity Stream) aggregates a user's activity from external services (RSS feeds, etc.) into per-user activity stream entities.
The configuration route does not sufficiently check that the user editing it is the account owner (or a user administrator) leading to an access bypass vulnerability.
Entity Reference Manager is an advanced administrative module for Drupal that allows site administrators to identify, analyze, and replace entity references across the system.
The module does not sufficiently restrict access to all entity management operations. Users who can view content can access the entity merge functionality and delete arbitrary nodes, taxonomy terms, or media entities.
The Block AJAX module enables you to load blocks asynchronously via Ajax.
The module doesn't sufficiently validate user-supplied data which is used to construct a block. In the worst case scenario, this can lead to PHP Object Injection and Remote Code Execution.
The vulnerability is mitigated by the fact that it only affects sites that have Layout Builder enabled (or another block plugin that handles the data this module passes to it in a potentially unsafe way).
Please see the release notes for details of potentially breaking changes.
The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration.
When the "Allow HTML description" option is enabled, slide descriptions are rendered using the raw stored field value instead of the field's rendered output. This bypasses Drupal's text format filtering and output sanitization mechanisms.
This vulnerability affects sites that use a formatted text field as the carousel description source and have enabled the "Allow HTML description" option.
This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.
The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint.
This module enables you to combine multiple image styles into a single image derivative.
The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.
Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.
This module enables you to use AI to fill in or replace text in CKEditor.
The module doesn't sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.
This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.
The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.
This module provides integration of the tawk.to live chat for Drupal sites.
The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.
This module enables sites to block access for the administrative user account (user 1) or users with the administrator role.
The module does not sufficiently enforce these access restrictions across all supported authentication mechanisms. As a result, a blocked administrative user may still be able to authenticate through certain alternative authentication methods.
This vulnerability is mitigated by the fact that an attacker must possess valid credentials for a user with the administrator role, and must authenticate using a less commonly used authentication mechanism.
This module enables you to provide information and options about cookie usage.
The module does not sufficiently filter input submitted through the Cookiecuttr administration form. This could allow specially crafted values to be stored and later rendered without adequate sanitization, resulting in a cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission administer cookiecuttr.
This module enables you to add mermaid diagram that displays either inline on an entity or optionally in a modal.
The module doesn't sufficiently respect default revision behavior and does not properly limit access to the modal content.
This vulnerability is mitigated by the fact that an attacker must have the modal display option enabled for the field, or otherwise know the route of the modal and entity ID.
This module enables REST endpoints for a decoupled Commerce experience which allow for remote order creation.
The module doesn't sufficiently sanitize order data passed into the order creation endpoint, which allows for potentially unsafe order properties to be set on an order.
The Cloud module enables users to manage cloud resources through Drupal.
The module does not sufficiently sanitize user-controlled Git branch and repository URL values before passing them to shell commands in the Kubernetes integration. This vulnerability allows an attacker to execute arbitrary operating-system commands as the web-server user.
The Cloud module enables users to manage cloud infrastructure through Drupal.
The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.
The Webform module allows site builders to create forms, collect submissions, and render submitted values in configurable formats.
Webform does not sufficiently exclude certain format templates from token replacement. This can allow an attacker to submit data that is evaluated as template code when a submission is rendered. Depending on the site configuration and enabled modules, this may lead to information disclosure, stored cross-site scripting, or remote code execution.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Webform did not sufficiently guard user-specific access rules against a malformed saved configuration. Under certain site-specific conditions, an access rule intended to grant submission access only to selected user accounts could also grant access to anonymous users.
This vulnerability is mitigated by the fact that the bypass depends on malformed saved access-rule configuration.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module did not sufficiently restrict access to certain submission view modes. Under certain conditions, a user who can view a submission could access a more permissive view mode and see fields that would otherwise be restricted.
This vulnerability is mitigated by the fact that an attacker must already have access to view the affected submission.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Form submissions may include uploaded files.
The module does not sufficiently force certain uploaded file types to download when served. Under certain site configurations, a file uploaded through a webform could be rendered inline by a browser, resulting in a cross-site scripting vulnerability.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Forms may be displayed in blocks.
Webform does not sufficiently validate an optional token query value before using it. Under specific configurations where a Webform is rendered for anonymous visitors, a malicious request can cause the request to consume significant resources leading to a Denial of Service.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Site builders may also configure handlers for processing submissions, including email handlers that may include uploaded files as attachments.
In affected configurations, Webform did not sufficiently validate a managed file upload element when processing a new submission. A user with access to submit a vulnerable webform could potentially access other managed files they were not authorized to view.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module does not sufficiently validate requested filenames when serving generated submission exports. Under certain configurations, a user with permission to view submission results for one webform may be able to access or remove files from the configured export temporary directory that were not generated for that webform.