One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-063

Project machine name: 
one_time_password
Date: 
2025-May-14
CVE IDs: 
CVE-2025-48012

This module enables you to allow users to include a second authentication method in addition to password authentication.

The module doesn't sufficiently prevent the same TFA token within a 30 second window.

This vulnerability is mitigated by the fact that an attacker must obtain a valid username/password and second factor.

One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-062

Project machine name: 
one_time_password
Date: 
2025-May-14
CVE IDs: 
CVE-2025-48011

This module enables you to allow users to include a second authentication method in addition to password authentication.

The module doesn't sufficiently prevent TFA from being bypassed when using the REST login routes.

A new requirements check has been added to the status report so other authentication providers can be assessed to check if they also allow for this bypass.

This vulnerability is mitigated by the fact that an attacker must obtain a valid username/password.

One Time Password - Moderately critical - Access bypass - SA-CONTRIB-2025-061

Project machine name: 
one_time_password
Date: 
2025-May-14
CVE IDs: 
CVE-2025-48010

This module enables you to allow users to include a second authentication method in addition to password authentication.

The module doesn't sufficiently prevent one time login links from bypassing TFA.

This vulnerability is mitigated by the fact that an attacker must have access to an email account attached to a user or a valid one time password link for a user.

Single Content Sync - Moderately critical - Access bypass - SA-CONTRIB-2025-060

Project machine name: 
single_content_sync
Date: 
2025-May-14
CVE IDs: 
CVE-2025-48009

This module enables you to seamlessly migrate and deploy content across environments, eliminating manual steps. It simplifies the process by exporting content to a YML file or a ZIP archive, which can be imported into another environment effortlessly.

While the export feature rightfully bypasses implemented access controls, enabling it to extract all entity data, including private and confidential information, to the mentioned formats, it fails to adequately safeguard the generated output.

Events Log Track - Moderately critical - Denial of Service - SA-CONTRIB-2025-059

Project machine name: 
events_log_track
Date: 
2025-May-14
CVE IDs: 
CVE-2025-4416

The Events Log Track module enables you to log specific events on a Drupal site.

The module doesn't sufficiently mitigate resource consumption for certain requests which allows a Denial of Service attack.

Piwik PRO - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-058

Project machine name: 
piwik_pro
Date: 
2025-May-14
CVE IDs: 
CVE-2025-4415

This module enables you to add the Piwik Pro web statistics tracking system to your website.

The module does not check the JS code that is loaded on the website. So a user with the "Administer Piwik Pro" permission could configure the module to load JS from a malicious website.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer piwik pro" to access the settings form where this can be configured.

Advanced File Destination - Critical - Multiple vulnerabilities - SA-CONTRIB-2025-057

Project machine name: 
advanced_file_destination
Date: 
2025-May-14

The Advanced File Destination module enhances file upload management in Drupal by allowing users to choose and create custom directories during file uploads.

The module has multiple vulnerabilities that were reported through the Drupal Security Team's coordinated vulnerability process. The project maintainer did not follow the terms and conditions for hosting projects on drupal.org that are opted into security coverage, so the module is losing its security coverage. The private issues may be made public at the discretion of the reporter and maintainer.

Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-056

Project machine name: 
miniorange_2fa
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47710

The module enables you to add second-factor authentication in addition to the default Drupal login.

The module does not sufficiently ensure that known login routes are protected.

This vulnerability is mitigated by the fact that an attacker must obtain the user's username and password.

Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-055

Project machine name: 
miniorange_2fa
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47709

The module enables you to add second-factor authentication in addition to the default Drupal login.

The module doesn't sufficiently protect certain sensitive routes, allowing an attacker to view or modify various TFA-related settings.

Enterprise MFA - TFA for Drupal - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-054

Project machine name: 
miniorange_2fa
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47708

The module enables you to add second-factor authentication in addition to the default Drupal login.

The module doesn't sufficiently protect certain routes from Cross Site Request Forgery (CSRF) attacks.

Enterprise MFA - TFA for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2025-053

Project machine name: 
miniorange_2fa
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47707

The module enables you to add second-factor authentication in addition to the default Drupal login.

The module doesn't invoke two factor authentication (2FA) for the password reset option.

This vulnerability is mitigated by the fact that an attacker must have access to the password reset link.

Enterprise MFA - TFA for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2025-052

Project machine name: 
miniorange_2fa
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47706

The module enables you to add second-factor authentication in addition to the default Drupal login.

The module doesn't sufficiently check whether the TOTP token is already used or not for authenticator-based second-factor methods.

This vulnerability is mitigated by the fact that an attacker must have a username, password and TOTP token generated within the last 5 minutes.

IFrame Remove Filter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-051

Project machine name: 
iframeremove
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47705

This module enables you to add a filter to text formats (Full HTML, Filtered HTML), which will remove every iframe where the "src" is not on the allowlist.

The module doesn't sufficiently filter these iframes in certain situations.

This vulnerability is mitigated by the fact that an attacker must be able to edit content that allows iframes.

Klaro Cookie & Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-050

Project machine name: 
klaro
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47704

Klaro Cookie & Consent Management module is used for consent management for cookies and external sources. It makes changes to the markup to enable or disable loading.

The module doesn't sufficiently sanitize data attributes allowing persistent Cross Site Scripting (XSS) attacks.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-049

Project machine name: 
cookies
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47703

The COOKIES module protects users from executing JavaScript code provided by third parties, e.g., to display ads or track user data without consent.

The cookies_asset_injector module (a sub-module of the COOKiES module) also allows inline JavaScript to be included in consent management. However, this does not adequately check whether the provided JavaScript code originates from authorized users.

A potential attacker would at least need permission to create and publish HTML (e.g. content or comments).

oEmbed Providers - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-048

Project machine name: 
oembed_providers
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47702

This module extends the core Media module and allows site creators to permit oEmbed providers in addition to YouTube and Vimeo, which are deemed trustworthy by the Drupal Security Team.

The module doesn't sufficiently mark its administrative permission as restricted, creating the possibility for the permission to be granted too broadly and to users without the ability to adequately vet providers. A malicious provider could execute a Cross Site Scripting (XSS) attack.

Restrict route by IP - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-047

Project machine name: 
restrict_route_by_ip
Date: 
2025-May-07
CVE IDs: 
CVE-2025-47701

The Restrict route by IP module provides an interface to manage route restriction by IP address.

The module doesn't sufficiently protect certain routes from CSRF attacks.

This vulnerability is mitigated by the fact that you need to know the route machine name.

Search API Solr - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-046

Project machine name: 
search_api_solr
Date: 
2025-April-23
CVE IDs: 
CVE-2025-3907

This module provides support for creating searches using the Apache Solr search engine and the Search API Drupal module.

The module doesn't sufficiently protect certain routes from CSRF attacks.

This vulnerability is mitigated by the fact that a site admin would have to perform further steps after the attack for it to have any effect.

Sportsleague - Critical - Unsupported - SA-CONTRIB-2025-045

Project machine name: 
sportsleague
Date: 
2025-April-23
CVE IDs: 
CVE-2025-3904

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

UEditor - 百度编辑器 - Critical - Unsupported - SA-CONTRIB-2025-044

Project machine name: 
ueditor
Date: 
2025-April-23
CVE IDs: 
CVE-2025-3903

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Block Class - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-043

Project machine name: 
block_class
Date: 
2025-April-23
CVE IDs: 
CVE-2025-3902

Block Class enables you to add custom attributes to blocks.

The module did not sufficiently sanitize custom attribute input, allowing for potential XSS attacks when malicious JavaScript was injected as a custom attribute.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer block classes".

Bootstrap Site Alert - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-042

Project machine name: 
bootstrap_site_alert
Date: 
2025-April-23
CVE IDs: 
CVE-2025-3901

This module enables you to put a site wide bootstrap themed alert message on the top of every page.

The module doesn't sufficiently filter text input when leading to a possible XSS attacks.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer bootstrap site alerts".

Colorbox - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-041

Project machine name: 
colorbox
Date: 
2025-April-23
CVE IDs: 
CVE-2025-3900

Colorbox is a module that allows Images, and iframed or inline content to be displayed in a modal above the current page.

The Colorbox module doesn't sufficiently sanitize data attributes before opening modals.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

Drupal 8 Google Optimize Hide Page - Critical - Unsupported - SA-CONTRIB-2025-040

Project machine name: 
d8_google_optimize_hide_page
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3739

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Google Optimize - Critical - Unsupported - SA-CONTRIB-2025-039

Project machine name: 
google_optimize
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3738

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Google Maps: Store Locator - Critical - Unsupported - SA-CONTRIB-2025-038

Project machine name: 
gmap_store_locator
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3737

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Simple GTM - Critical - Unsupported - SA-CONTRIB-2025-037

Project machine name: 
simple_gtm
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3736

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Panelizer (obsolete) - Critical - Unsupported - SA-CONTRIB-2025-036

Project machine name: 
panelizer
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3735

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Stage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035

Project machine name: 
stage_file_proxy
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3734

Stage File Proxy is a general solution for getting production files on a development server on demand.

The module doesn't sufficiently validate the existence of remote files prior to attempting to download and create them. An attacker could send many requests and exhaust disk resources.

This vulnerability is mitigated by the fact it only affects sites where the Origin is configured with a trailing slash. Sites that cannot upgrade immediately can confirm they do not have a trailing slash or remove the trailing slash to mitigate the issue.

baguetteBox.js - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-034

Project machine name: 
baguettebox
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3733

The baguetteBox.js module provides integration with baguetteBox.js library.

The module doesn't sufficiently sanitize user-supplied text values leading to a cross site scripting vulnerability.

Panels - Critical - Access bypass - SA-CONTRIB-2025-033

Project machine name: 
panels
Date: 
2025-April-09
CVE IDs: 
CVE-2025-3474

Panels enables administrators to add page variants within page manager, panelizer, etc to create custom pages.

The module doesn't sufficiently protect sensitive routes, allowing an attacker to view and modify blocks within variants without requiring appropriate permission.

Gif Player Field - Moderately critical - Cross site scripting - SA-CONTRIB-2025-032

Project machine name: 
gifplayer
Date: 
2025-April-09
CVE IDs: 
CVE-2025-31128

Gif Player Field creates a simple file field types that allows you to upload the GIF files and configure the output for this using the Field Formatters.

The module uses GifPlayer jQuery library to render the GIF according to configured setups for the Field Formatter. The external Gif Player Library doesn't satinize the attributes properly when rendering the widget, allowing a malicious user to run XSS attacks.

ECA: Event - Condition - Action - Critical - Cross site request forgery - SA-CONTRIB-2025-031

Project machine name: 
eca
Date: 
2025-April-09
CVE IDs: 
CVE-2025-3131

This module enables you to define automations on your Drupal site.

The module doesn't sufficiently protect certain routes from CSRF attacks.

This vulnerability can be mitigated by disabling the "eca_ui" submodule, which leaves ECA functionality intact, but the vulnerable routes will no longer be available.

WEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030

Project machine name: 
webt
Date: 
2025-April-09
CVE IDs: 
CVE-2025-3475

This module enables you to translate nodes, configuration, UI strings automatically.

The module doesn't sufficiently validate the incoming API response when using eTranslation integration, which has an asynchronous workflow. Specially crafted requests could overwrite entities and translations of entities with arbitrary content and create load on the system leading to a Denial of Service.

Obfuscate - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-029

Project machine name: 
obfuscate
Date: 
2025-April-02
CVE IDs: 
CVE-2025-3130

This module enables you to obfuscate email addresses, to avoid them being easily available to spammers.

The module doesn't sufficiently sanitise input when ROT13 encoding is used.
This vulnerability is mitigated by the fact that an attacker must have a role with the ability to enter specific HTML tag attributes. In a default Drupal installation this would require the administrator role and use of the Full HTML text format. It also requires that the ROT13 encoding be enabled in Obfuscate settings.

Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-028

Project machine name: 
access_code
Date: 
2025-April-02
CVE IDs: 
CVE-2025-3129

This module enables users to log in using a short access code instead of providing a username/password combination.

The module doesn't sufficiently protect against brute force attacks to guess a user's access code.

This vulnerability is mitigated by the fact that access code based logins are off by default and only enabled for accounts that enable it. Sites could mitigate the issue without updating by:

TacJS - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-027

Project machine name: 
tacjs
Date: 
2025-April-02
CVE IDs: 
CVE-2025-31476

This module enables sites to comply with the European cookie law using tarteaucitron.js.

The module doesn't sufficiently filter user-supplied markup inside of content leading to a persistent Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004

Project machine name: 
drupal
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31675

Drupal core Link field attributes are not sufficiently sanitized, which can lead to a Cross Site Scripting vulnerability (XSS).

This vulnerability is mitigated by that fact that an attacker would need to have the ability to add specific attributes to a Link field, which typically requires edit access via core web services, or a contrib or custom module.

Sites with the Link module disabled or that do not use any link fields are not affected.

Formatter Suite - Moderately critical - Cross site scripting - SA-CONTRIB-2025-026

Project machine name: 
formatter_suite
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31697

Formatter Suite provides a suite of field formatters to help present numbers, dates, times, text, links, entity references, files, and images. The module provides a custom formatter for link fields.

Drupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).

A separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.

RapiDoc OAS Field Formatter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-025

Project machine name: 
rapidoc_elements_field_formatter
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31696

This module can be used to render Open API Documentation using the RapiDoc library. The module provides a custom formatter for link fields.

Drupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).

A separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.

Link field display mode formatter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-024

Project machine name: 
link_field_display_mode_formatter
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31695

This module adds a formatter for link fields that displays the current entity with another view mode inside the link.

Drupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).

A separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.

Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2025-023

Project machine name: 
tfa
Date: 
2025-March-05
CVE IDs: 
CVE-2025-31694

This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.

The module does not sufficiently ensure that known login routes are not overridden by third-party modules which can allow an access bypass to occur.

This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.

AI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022

Project machine name: 
ai
Date: 
2025-March-05
CVE IDs: 
CVE-2025-31693

The AI Automators module (a submodule of AI) enables you to create different automated tasks that fills out a field data using LLM outputs.

The module contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Arbitrary File Deletion. It may be possible to escalate this attack to Remote Code Execution. It is not directly exploitable.

AI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021

Project machine name: 
ai
Date: 
2025-March-05
CVE IDs: 
CVE-2025-31692

The AI Automators module (a submodule of AI) enables you to create different automated tasks that fills out field data using LLM outputs.

The module doesn't sufficiently sanitize input before passing it to the underlying shell as part of a command for execution, allowing an attacker to run arbitrary commands.

The vulnerability exists in optional Automator Types which are part of the optional AI Automators (sub)module.

The AI module is included in Drupal CMS.

OAuth2 Server - Moderately critical - Access bypass - SA-CONTRIB-2025-020

Project machine name: 
oauth2_server
Date: 
2025-February-26
CVE IDs: 
CVE-2025-31691

Provides OAuth2 server functionality based on the oauth2-server-php library.

The module does not consistently enforce admin configurations allowing users on a disabled server to still authenticate.

Cache Utility - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-019

Project machine name: 
cache_utility
Date: 
2025-February-26
CVE IDs: 
CVE-2025-31690

The Cache Utility module provides an ability to view status and flush various caches.

The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when flushing a cache.

General Data Protection Regulation - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-018

Project machine name: 
gdpr
Date: 
2025-February-26
CVE IDs: 
CVE-2025-31689

The GDPR Task submodule enables you to create GDPR tasks.

The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when creating tasks.

Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

Project machine name: 
drupal
Date: 
2025-February-19
CVE IDs: 
CVE-2025-31674

Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Arbitrary File Inclusion. Techniques exist to escalate this attack to Remote Code Execution. It is not directly exploitable.

This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize(). There are no such known exploits in Drupal core.

Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002

Project machine name: 
drupal
Date: 
2025-February-19
CVE IDs: 
CVE-2025-31673

Bulk operations allow authorized users to modify several nodes at once from the Content page (/admin/content). A site builder can also add bulk operations to other pages using Views.

A bug in the core Actions system allows some users to modify some fields using bulk actions that they do not have permission to modify on individual nodes.

This vulnerability is mitigated by the fact that an attacker must have permission to access /admin/content or other, custom views and to edit nodes.

Drupal core - Critical - Cross site scripting - SA-CORE-2025-001

Project machine name: 
drupal
Date: 
2025-February-19
CVE IDs: 
CVE-2025-3057

Drupal core doesn't sufficiently filter error messages under certain circumstances, leading to a reflected Cross Site Scripting vulnerability (XSS).

Sites are encouraged to update. There are not yet public documented steps to exploit this, but there may be soon given the nature of this issue.

This issue is being protected by Drupal Steward. Sites that use Drupal Steward are already protected, but are still encouraged to upgrade in the near future.

Pages

Subscribe with RSS Subscribe to Security advisories