Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

Project machine name: 
slick
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81160

Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.

Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.

Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.

Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116

Project machine name: 
monster_menus
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81201

This module enables you to create one or more multisites with highly granular page permissions.

The module doesn't sufficiently sanitize HTML code contained in the page name when displayed in the built-in tree browser. This results in a cross-site scripting vulnerability that may allow attackers to execute arbitrary JavaScript in the context of the user’s session.

This vulnerability is mitigated by the fact that an attacker must have the ability to create pages whose page title supports HTML.

LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

Project machine name: 
ldap_auth
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81205

This module enables users to authenticate using LDAP or Active Directory credentials.

The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.

Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114

Project machine name: 
entity_pdf
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81164

The Entity PDF module can create a PDF from any entity based on any View mode.

This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.

Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113

Project machine name: 
entity
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81158

The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.

The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.

This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.

DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112

Project machine name: 
dxpr_builder
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81162

The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata.

The 2.x version of the module does not sufficiently restrict access to API credentials in JavaScript settings. When AI agent features are enabled, the token is exposed to all page visitors (including anonymous users) via drupalSettings.

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111

Project machine name: 
disable_login
Date: 
2026-August-26
CVE IDs: 
CVE-2026-16647

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may remain accessible until caches are cleared. An attacker may continue to access the login page despite the restriction having been enabled.

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110

Project machine name: 
disable_login
Date: 
2026-August-26
CVE IDs: 
CVE-2026-18260

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.

Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109

Project machine name: 
digital_signage_framework
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81166

The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic blocks on a display.

The route did not check whether the requester was a signage device, nor whether the requested block was one that the module delivers to displays. As a result, an anonymous visitor could read the rendered content of blocks they were not meant to see.

This vulnerability is mitigated by the fact that many block plugins perform their own access checks on the content they display, which limits what can be disclosed through this route.

Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108

Project machine name: 
datafield
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81269

This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.

The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.

Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107

Project machine name: 
content_moderation_notifications
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81161

The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted.

A site administrator might inadvertently grant this permission to less-trusted users. This would allow those users to execute Twig within email templates, and to gain access to functionality and information intended only for highly trusted administrators.

Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106

Project machine name: 
commerce_cybersource
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81159

This module integrates Drupal Commerce with the CyberSource payment gateway.

The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.

This issue only affects the Secure Acceptance Hosted Checkout gateway integration.

CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105

Project machine name: 
captcha_protected_page
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81168

This module enables site administrators to require CAPTCHA confirmation on specific pages.

The module does not sufficiently validate its CAPTCHA verification cookies. Under certain circumstances, an unauthenticated user or automated bot can forge the cookie and bypass CAPTCHA verification entirely.

Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104

Project machine name: 
blazy
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81165

This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode.

The module does not consistently check entity view access. If a user has access to a Blazy-enabled text format, this allows them to render a field from an entity they are not permitted to view.

The issue is mitigated by the fact that the shortcode does not expose the entire entity. Only fields that the shortcode can render are vulnerable.

Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103

Project machine name: 
address_suggestion
Date: 
2026-August-26
CVE IDs: 
CVE-2026-81167

The Address Suggestion module provides address autocomplete functionality using configured address providers.

The module doesn't sufficiently sanitize address suggestion data returned by configured providers, which can lead to a cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to inject malicious content into data returned by a configured address provider, and a user must perform a search that returns the malicious suggestion.

Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102

Project machine name: 
screenshot
Date: 
2026-August-19
CVE IDs: 
CVE-2026-76759
CVE-2026-76782

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that is unsupported for security reasons.

Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101

Project machine name: 
postlight_parser
Date: 
2026-August-19
CVE IDs: 
CVE-2026-76758

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that is unsupported for security reasons.

Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100

Project machine name: 
gammu_smsd
Date: 
2026-August-19
CVE IDs: 
CVE-2026-76755
CVE-2026-76756
CVE-2026-76757

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that is unsupported for security reasons.

Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099

Project machine name: 
quicktabs
Date: 
2026-August-12
CVE IDs: 
CVE-2026-73477

This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance.

The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant for node tabs and block plugins, and performed no access check for reusable custom blocks. Content that should have been denied was therefore rendered — for example, an unpublished node or unpublished reusable custom block could be shown to users without permission to view it.

External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098

Project machine name: 
externalauth
Date: 
2026-August-12
CVE IDs: 
CVE-2026-73476

This module enables you to authenticate Drupal users against external identity providers.

The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database collation configurations.

This vulnerability is minimally mitigated by the fact that it affects only sites using impacted MySQL or MariaDB collation settings for the module’s authentication mapping storage. Affected collations are quite common so all sites are encouraged to upgrade.

Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097

Project machine name: 
entity_share_websub
Date: 
2026-August-12
CVE IDs: 
CVE-2026-73474

This module enables you to share content between sites in a hub - subscriber model.

Certain inputs were not sufficiently validated, allowing an attacker to achieve server-side request forgery attacks.

Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096

Project machine name: 
diff
Date: 
2026-August-12
CVE IDs: 
CVE-2026-73478

This module enables you to view the differences between revisions on any entity type.

The module doesn't sufficiently restrict access to non-node entity revision diffs.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to view the entity.

Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095

Project machine name: 
commerce_paypal
Date: 
2026-August-12
CVE IDs: 
CVE-2026-73475

This module enables you to pay for Commerce transactions using Paypal.

The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment.

This vulnerability only affects sites using the Payflow Link payment gateway.

Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094

Project machine name: 
entity_browser
Date: 
2026-August-05
CVE IDs: 
CVE-2026-18986

The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.

The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.

Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093

Project machine name: 
edit_in_place_field
Date: 
2026-August-05
CVE IDs: 
CVE-2026-18985

This module provides formatters to allow in-place editing in a View or other display (full content, teaser...).

The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission".

Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092

Project machine name: 
powerful_surveys
Date: 
2026-July-29
CVE IDs: 
CVE-2026-18261

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091

Project machine name: 
disable_login
Date: 
2026-July-29
CVE IDs: 
CVE-2026-18260

An advisory for this issue has been issued at https://www.drupal.org/sa-contrib-2026-110 and an additional issue was identified and fixed via https://www.drupal.org/sa-contrib-2026-111

This module is now resupported. See that advisory for more details.

Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

Project machine name: 
tca
Date: 
2026-July-29
CVE IDs: 
CVE-2026-18259

The Token Content Access module enables site administrators to provide access to content using access tokens.

The module does not sufficiently protect access token comparison in some cases. This could allow a persistent attacker to use a timing attack to guess a valid access token and bypass access restrictions for content protected by this module.

Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089

Project machine name: 
development_environment
Date: 
2026-July-22
CVE IDs: 
CVE-2026-15088

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088

Project machine name: 
photoswipe
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16645

The Photoswipe Drupal module provides integration for the widely used PhotoSwipe lightbox library to display / zoom images in lightbox galleries using the provided image formatters.

The module didn't sufficiently check access permissions, when viewing an image using the photoswipe image gallery display formatter, in versions < 3.0.4 (Drupal 8) or < 3.2.0 (Drupal 9 / Drupal 10).

Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Project machine name: 
webform_rest
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16644

This module enables you to retrieve and submit webform submissions via REST endpoints.

The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Security advisory coverage removed - QA Accounts - PSA-2026-07-22

Date: 
2026-July-22

QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.

Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

Project machine name: 
lunr_filters
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16643

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

Project machine name: 
email_login_otp
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16642

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

Project machine name: 
commerce_elavon
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16641

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

Project machine name: 
pankm
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16646

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

Project machine name: 
search_api_autocomplete
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16640

This module enables you to add autocomplete suggestions for search forms created with the Search API module.

The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.

Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

Project machine name: 
i18n_sso
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16639

In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.

The module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.

This vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.

Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080

Project machine name: 
media_folders
Date: 
2026-July-22
CVE IDs: 
CVE-2026-16638

This module provides a better UI for managing and selecting Media entities in a folder structure.

The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012

Project machine name: 
drupal
Date: 
2026-July-15
CVE IDs: 
CVE-2026-55805

The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.

This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011

Project machine name: 
drupal
Date: 
2026-July-15
CVE IDs: 
CVE-2026-15917

Drupal core 11.2 and above integrate the HTMX JavaScript library.

Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes.

Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010

Project machine name: 
drupal
Date: 
2026-July-15
CVE IDs: 
CVE-2026-15916

The Image module allows you to define and configure image fields.

The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private://.

This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images.

Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079

Project machine name: 
commerce_guest_registration
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15089

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078

Project machine name: 
clean_node_api
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15087

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077

Project machine name: 
raw_formatter
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15086

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076

Project machine name: 
ai_seo
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15085

The AI SEO/GEO Analyzer module generates SEO/GEO analysis reports by sending content of an entity (including its comments) to an LLM, then converts the model's Markdown response to HTML and stores it for display to privileged users.

The generated HTML was rendered without passing through Drupal's filtering pipeline, so it relied on the LLM output being safe. Under certain circumstances a crafted prompt injection — planted in content that is included in the analysis — can cause the LLM to emit markup that results in stored Cross-site Scripting when the report is later viewed.

UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075

Project machine name: 
ui_patterns
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15084

This module enables you to use Single Directory Components in site building (views, field formatters, blocks, layouts) and it improves the Developer Experience (DX) with SDC.

The module doesn't sufficiently sanitize the markup passed to components under certain scenarios.

This vulnerability is mitigated by the fact that an attacker must be able to create or update content rendered by UI Patterns.

ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074

Project machine name: 
eca
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15083

The Events, Conditions, Actions (ECA) module's Render submodule enables you to build render arrays and render inline Twig templates as part of no-code ECA models.

The module doesn't sufficiently sanitize template code when rendering, which can lead to information disclosure.

This vulnerability is mitigated by the fact that a site must be running an ECA model that uses the "Render: Twig" action on a data flow.

Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073

Project machine name: 
siteimprove_analytics
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15082

The module doesn't sufficiently sanitize the Siteimprove Analytics identification code when inserting the JavaScript tracking code; this could be exploited to achieve Cross-Site Scripting (XSS).

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer siteimprove_analytics".

Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072

Project machine name: 
location_selector
Date: 
2026-July-08
CVE IDs: 
CVE-2026-15081

The Location Selector module provides a Views filter for selecting location values.

One of the provided Views filters does not sufficiently sanitize values that may come from user input, resulting in a SQL injection vulnerability.

This vulnerability is mitigated by the fact that a View must exist that uses the affected filter and is configured to accept user input.

Pages

Subscribe with RSS Subscribe to Security advisories