Simple GTM - Critical - Unsupported - SA-CONTRIB-2025-037

Project machine name: 
simple_gtm
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3736

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Panelizer (obsolete) - Critical - Unsupported - SA-CONTRIB-2025-036

Project machine name: 
panelizer
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3735

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Stage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035

Project machine name: 
stage_file_proxy
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3734

Stage File Proxy is a general solution for getting production files on a development server on demand.

The module doesn't sufficiently validate the existence of remote files prior to attempting to download and create them. An attacker could send many requests and exhaust disk resources.

This vulnerability is mitigated by the fact it only affects sites where the Origin is configured with a trailing slash. Sites that cannot upgrade immediately can confirm they do not have a trailing slash or remove the trailing slash to mitigate the issue.

baguetteBox.js - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-034

Project machine name: 
baguettebox
Date: 
2025-April-16
CVE IDs: 
CVE-2025-3733

The baguetteBox.js module provides integration with baguetteBox.js library.

The module doesn't sufficiently sanitize user-supplied text values leading to a cross site scripting vulnerability.

Panels - Critical - Access bypass - SA-CONTRIB-2025-033

Project machine name: 
panels
Date: 
2025-April-09
CVE IDs: 
CVE-2025-3474

Panels enables administrators to add page variants within page manager, panelizer, etc to create custom pages.

The module doesn't sufficiently protect sensitive routes, allowing an attacker to view and modify blocks within variants without requiring appropriate permission.

Gif Player Field - Moderately critical - Cross site scripting - SA-CONTRIB-2025-032

Project machine name: 
gifplayer
Date: 
2025-April-09
CVE IDs: 
CVE-2025-31128

Gif Player Field creates a simple file field types that allows you to upload the GIF files and configure the output for this using the Field Formatters.

The module uses GifPlayer jQuery library to render the GIF according to configured setups for the Field Formatter. The external Gif Player Library doesn't satinize the attributes properly when rendering the widget, allowing a malicious user to run XSS attacks.

ECA: Event - Condition - Action - Critical - Cross site request forgery - SA-CONTRIB-2025-031

Project machine name: 
eca
Date: 
2025-April-09
CVE IDs: 
CVE-2025-3131

This module enables you to define automations on your Drupal site.

The module doesn't sufficiently protect certain routes from CSRF attacks.

This vulnerability can be mitigated by disabling the "eca_ui" submodule, which leaves ECA functionality intact, but the vulnerable routes will no longer be available.

WEB-T - Moderately critical - Access bypass, Denial of service - SA-CONTRIB-2025-030

Project machine name: 
webt
Date: 
2025-April-09
CVE IDs: 
CVE-2025-3475

This module enables you to translate nodes, configuration, UI strings automatically.

The module doesn't sufficiently validate the incoming API response when using eTranslation integration, which has an asynchronous workflow. Specially crafted requests could overwrite entities and translations of entities with arbitrary content and create load on the system leading to a Denial of Service.

Obfuscate - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-029

Project machine name: 
obfuscate
Date: 
2025-April-02
CVE IDs: 
CVE-2025-3130

This module enables you to obfuscate email addresses, to avoid them being easily available to spammers.

The module doesn't sufficiently sanitise input when ROT13 encoding is used.
This vulnerability is mitigated by the fact that an attacker must have a role with the ability to enter specific HTML tag attributes. In a default Drupal installation this would require the administrator role and use of the Full HTML text format. It also requires that the ROT13 encoding be enabled in Obfuscate settings.

Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-028

Project machine name: 
access_code
Date: 
2025-April-02
CVE IDs: 
CVE-2025-3129

This module enables users to log in using a short access code instead of providing a username/password combination.

The module doesn't sufficiently protect against brute force attacks to guess a user's access code.

This vulnerability is mitigated by the fact that access code based logins are off by default and only enabled for accounts that enable it. Sites could mitigate the issue without updating by:

TacJS - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-027

Project machine name: 
tacjs
Date: 
2025-April-02
CVE IDs: 
CVE-2025-31476

This module enables sites to comply with the European cookie law using tarteaucitron.js.

The module doesn't sufficiently filter user-supplied markup inside of content leading to a persistent Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004

Project machine name: 
drupal
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31675

Drupal core Link field attributes are not sufficiently sanitized, which can lead to a Cross Site Scripting vulnerability (XSS).

This vulnerability is mitigated by that fact that an attacker would need to have the ability to add specific attributes to a Link field, which typically requires edit access via core web services, or a contrib or custom module.

Sites with the Link module disabled or that do not use any link fields are not affected.

Formatter Suite - Moderately critical - Cross site scripting - SA-CONTRIB-2025-026

Project machine name: 
formatter_suite
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31697

Formatter Suite provides a suite of field formatters to help present numbers, dates, times, text, links, entity references, files, and images. The module provides a custom formatter for link fields.

Drupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).

A separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.

RapiDoc OAS Field Formatter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-025

Project machine name: 
rapidoc_elements_field_formatter
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31696

This module can be used to render Open API Documentation using the RapiDoc library. The module provides a custom formatter for link fields.

Drupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).

A separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.

Link field display mode formatter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-024

Project machine name: 
link_field_display_mode_formatter
Date: 
2025-March-19
CVE IDs: 
CVE-2025-31695

This module adds a formatter for link fields that displays the current entity with another view mode inside the link.

Drupal core does not sufficiently sanitize link element attributes, which can lead to a Cross Site Scripting vulnerability (XSS).

A separate fix for Drupal core has been released but this module requires a concurrent release to make use of the Drupal core fix.

Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2025-023

Project machine name: 
tfa
Date: 
2025-March-05
CVE IDs: 
CVE-2025-31694

This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.

The module does not sufficiently ensure that known login routes are not overridden by third-party modules which can allow an access bypass to occur.

This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.

AI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022

Project machine name: 
ai
Date: 
2025-March-05
CVE IDs: 
CVE-2025-31693

The AI Automators module (a submodule of AI) enables you to create different automated tasks that fills out a field data using LLM outputs.

The module contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Arbitrary File Deletion. It may be possible to escalate this attack to Remote Code Execution. It is not directly exploitable.

AI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021

Project machine name: 
ai
Date: 
2025-March-05
CVE IDs: 
CVE-2025-31692

The AI Automators module (a submodule of AI) enables you to create different automated tasks that fills out field data using LLM outputs.

The module doesn't sufficiently sanitize input before passing it to the underlying shell as part of a command for execution, allowing an attacker to run arbitrary commands.

The vulnerability exists in optional Automator Types which are part of the optional AI Automators (sub)module.

The AI module is included in Drupal CMS.

OAuth2 Server - Moderately critical - Access bypass - SA-CONTRIB-2025-020

Project machine name: 
oauth2_server
Date: 
2025-February-26
CVE IDs: 
CVE-2025-31691

Provides OAuth2 server functionality based on the oauth2-server-php library.

The module does not consistently enforce admin configurations allowing users on a disabled server to still authenticate.

Cache Utility - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-019

Project machine name: 
cache_utility
Date: 
2025-February-26
CVE IDs: 
CVE-2025-31690

The Cache Utility module provides an ability to view status and flush various caches.

The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when flushing a cache.

General Data Protection Regulation - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-018

Project machine name: 
gdpr
Date: 
2025-February-26
CVE IDs: 
CVE-2025-31689

The GDPR Task submodule enables you to create GDPR tasks.

The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when creating tasks.

Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003

Project machine name: 
drupal
Date: 
2025-February-19
CVE IDs: 
CVE-2025-31674

Drupal core contains a potential PHP Object Injection vulnerability that (if combined with another exploit) could lead to Arbitrary File Inclusion. Techniques exist to escalate this attack to Remote Code Execution. It is not directly exploitable.

This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize(). There are no such known exploits in Drupal core.

Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002

Project machine name: 
drupal
Date: 
2025-February-19
CVE IDs: 
CVE-2025-31673

Bulk operations allow authorized users to modify several nodes at once from the Content page (/admin/content). A site builder can also add bulk operations to other pages using Views.

A bug in the core Actions system allows some users to modify some fields using bulk actions that they do not have permission to modify on individual nodes.

This vulnerability is mitigated by the fact that an attacker must have permission to access /admin/content or other, custom views and to edit nodes.

Drupal core - Critical - Cross site scripting - SA-CORE-2025-001

Project machine name: 
drupal
Date: 
2025-February-19
CVE IDs: 
CVE-2025-3057

Drupal core doesn't sufficiently filter error messages under certain circumstances, leading to a reflected Cross Site Scripting vulnerability (XSS).

Sites are encouraged to update. There are not yet public documented steps to exploit this, but there may be soon given the nature of this issue.

This issue is being protected by Drupal Steward. Sites that use Drupal Steward are already protected, but are still encouraged to upgrade in the near future.

Configuration Split - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-017

Project machine name: 
config_split
Date: 
2025-February-12
CVE IDs: 
CVE-2025-31688

This module enables you to create super sets of configuration and enable them conditionally, for example have some modules installed only in some environments.

The module does not use Cross Site Request Forgery (CSRF) tokens to protect routes for enabling or disabling a split.

SpamSpan filter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-016

Project machine name: 
spamspan
Date: 
2025-February-12
CVE IDs: 
CVE-2025-31687

This module enables your site to obfuscate Email addresses and prevent spambots to collect them.

The module doesn't sanitize HTML data attributes when an email address link is transformed to separate span HTML elements and then transformed back by JavaScript leading to a Cross Site Scripting (XSS) vulnerability.

This is mitigated by the fact an attacker must be able to insert span HTML elements with data attributes in the page.

Open Social - Less critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-015

Project machine name: 
social
Date: 
2025-February-12
CVE IDs: 
CVE-2025-31686

Open Social is a Drupal distribution for online communities, which ships with a default module to invite users to groups and events.

Invites for a specific user can be seen under certain conditions.

The issue is mitigated for events by the fact that social_event_max_enroll has to be enabled.

Open Social - Moderately critical - Access bypass - SA-CONTRIB-2025-014

Project machine name: 
social
Date: 
2025-February-12
CVE IDs: 
CVE-2025-31685

Open Social is a Drupal distribution for online communities, which ships with a default (optional) module social_language to make your platform multilingual.

Some site administration configuration does not correctly check access when trying to translate allowing unauthorised people to translate these parts.

The issue is mitigated by the fact that social_language needs to be enabled with more than 1 language.

OAuth2 Client - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-013

Project machine name: 
oauth2_client
Date: 
2025-February-05
CVE IDs: 
CVE-2025-31684

This module enables a developer to create dedicated OAuth2 clients for connecting to external APIs and other OAuth protected resources.

The module does not use Cross Site Request Forgery (CSRF) tokens to protect routes for enabling a client.

This vulnerability is mitigated by the fact that an attacker must know the machine name of the client and deceive another user with this permission.

Google Tag - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-012

Project machine name: 
google_tag
Date: 
2025-January-29
CVE IDs: 
CVE-2025-31683

This module enables you to integrate the site with the Google Tag Manager (GTM) application.

The module doesn't sufficiently validate the enabling or disabling of a tag container. The routes involved are not protected against Cross Site Request Forgery (CSRF).

This vulnerability is mitigated by the fact that an attacker needs to know the machine name of the container. The machine name is a random string, making an attack more difficult.

Google Tag - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-011

Project machine name: 
google_tag
Date: 
2025-January-29
CVE IDs: 
CVE-2025-31682

This module enables you to integrate the site with the Google Tag Manager (GTM) application.

The module doesn't have the "restrict access" flag on the "administer google_tag_container" permission. A user with this permission can load a GTM container that completely changes the page or inserts malicious JS, resulting in a cross site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the aforementioned permission.

Drupal Admin LTE theme - Critical - Unsupported - SA-CONTRIB-2025-010

Project machine name: 
druadmin_lte_theme
Date: 
2025-January-29
CVE IDs: 
CVE-2025-3062

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Authenticator Login - Critical - Access bypass - SA-CONTRIB-2025-009

Project machine name: 
alogin
Date: 
2025-January-29
CVE IDs: 
CVE-2025-31681

This module allows a site to setup two factor authentication via QR code using authenticator applications on mobile devices including phones.

The module does not properly protect its custom paths, allowing one user to access a different user's two factor configuration.

Matomo Analytics - Moderately critical - Cross site request forgery - SA-CONTRIB-2025-008

Project machine name: 
matomo
Date: 
2025-January-29
CVE IDs: 
CVE-2025-31680

This module enables you to add the Matomo web statistics tracking system to your website.

The Matomo Analytics Tag Manager sub-module allows you to add one or more Matomo tag containers on your website.

The module does not protect against Cross Site Request Forgeries on routes to enable or disable containers.

This vulnerability is mitigated by the fact that:

  • The website needs to have the submodule "Matomo Analytics Tag Manager" enabled.
  • An attacker must know the machine name of the container.

Ignition Error Pages - Critical - Cross Site Scripting - SA-CONTRIB-2025-007

Project machine name: 
ignition
Date: 
2025-January-22
CVE IDs: 
CVE-2025-31679

This module enables you to render error pages using the Ignition package.

The module disables certain Drupal core code and does not perform sufficient filtering, allowing HTML to be injected in certain situations leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that this module is for development purposes and is not intended to be installed on production environments.

Material Admin - Critical - Unsupported - SA-CONTRIB-2025-006

Project machine name: 
material_admin
Date: 
2025-January-22
CVE IDs: 
CVE-2025-3061

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Flattern – Multipurpose Bootstrap Business Profile - Critical - Unsupported - SA-CONTRIB-2025-005

Project machine name: 
flattern
Date: 
2025-January-22
CVE IDs: 
CVE-2025-3060

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

AI (Artificial Intelligence) - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-004

Project machine name: 
ai
Date: 
2025-January-22
CVE IDs: 
CVE-2025-31678

The AI logging sub-module enables you to log AI requests and responses for debugging and auditing purposes.

The module doesn't sufficiently check for access to view the preview listing of the logs. Full log details are correctly protected, and API keys are never logged.

This vulnerability is mitigated by the fact that it only affects sites using the AI Logging sub-module with 'Log requests' enabled in the AI Logging configuration page.

AI (Artificial Intelligence) - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-003

Project machine name: 
ai
Date: 
2025-January-15
CVE IDs: 
CVE-2025-31677

The Drupal AI module provides a framework for easily integrating Artificial Intelligence on any Drupal site using any kind of AI (from multiple vendors). The sub-modules AI Chatbot and AI Assistants API allow users to interact with the Drupal site via a 'chat' interface.

Profile Private - Critical - Unsupported - SA-CONTRIB-2025-002

Project machine name: 
profile_private
Date: 
2025-January-08
CVE IDs: 
CVE-2025-3059

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001

Project machine name: 
email_tfa
Date: 
2025-January-08
CVE IDs: 
CVE-2025-31676

This module enables you to do Two-Factor Authentication by email, using a user registered email to send a verification code to the user's email every time the user tries to log in to your site.

The module did not sufficiently protect against brute force attacks, allowing an attacker to bypass the second factor.

This vulnerability is mitigated by the fact the attacker must be able to present the username and first factor (i.e. password).

Drupal 7 End of Life - PSA-2025-01-06

Date: 
2025-January-06

Drupal core version 7 has reached end of life, and is no longer community supported on Drupal.org. This means that new releases of Drupal 7 core and contributed projects will no longer happen on Drupal.org and community support is no longer provided.

What this means for you:

Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076

Project machine name: 
social
Date: 
2024-December-11
CVE IDs: 
CVE-2024-13312

Open Social is a Drupal distribution for online communities, which ships with a default (optional) module social_file_private to ensure the images and files provided by the distribution are stored in the private instead of the public filesystem.

For installations of Open Social prior to version 11.8.0, after updating to 11.8.0 or higher, newly uploaded files were no longer stored in the private file system as intended. Instead, they were stored in the public file system.

Allow All File Extensions for file fields - Critical - Unsupported - SA-CONTRIB-2024-075

Project machine name: 
all_extensions
Date: 
2024-December-11
CVE IDs: 
CVE-2024-13311

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Git Utilities for Drupal - Critical - Unsupported - SA-CONTRIB-2024-074

Project machine name: 
git_utils
Date: 
2024-December-11
CVE IDs: 
CVE-2024-13310

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Login Disable - Critical - Access bypass - SA-CONTRIB-2024-073

Project machine name: 
login_disable
Date: 
2024-December-11
CVE IDs: 
CVE-2024-13309

This module enables you to prevent existing users from logging in to your Drupal site unless they know the secret key to add to the end of the ?q=user login form page.

The Login Disable module does not correctly prevent a user with a disabled login from logging in, allowing those users to by-pass the protection offered by the module.

This vulnerability is mitigated by the fact that an attacker must already have a user account to log in. This bug therefore allows users to log in even if their login is disabled.

Browser Back Button - Moderately critical - Cross site scripting - SA-CONTRIB-2024-072

Project machine name: 
browser_back_button
Date: 
2024-December-11
CVE IDs: 
CVE-2024-13308

This module provides a block that renders a link providing the functionality of a browser's back button.

The module does not sufficiently escape text entered by an administrator, resulting in a cross scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer blocks".

Entity Form Steps - Moderately critical - Cross site scripting - SA-CONTRIB-2024-071

Project machine name: 
entity_form_steps
Date: 
2024-December-04
CVE IDs: 
CVE-2024-13305

This module allows a site builder to create multi-step entity forms leveraging the Field Group field type plugins.

The module doesn't escape plain text administrative configurations. An attacker with admin access could inject arbitrary JavaScript code.

This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer [entity_type] form display' permission allowing access to configure entity form displays.

Minify JS - Moderately critical - Cross site request forgery - SA-CONTRIB-2024-070

Project machine name: 
minifyjs
Date: 
2024-December-04
CVE IDs: 
CVE-2024-13304

The Minify JS module allows a site administrator to minify all javascript files that exist in the site's code base and use those minified files on the front end of the website.

Several administrator routes are unprotected against Cross-Site Request Forgery (CRSF) attacks.

Download All Files - Critical - Access bypass - SA-CONTRIB-2024-069

Project machine name: 
download_all_files
Date: 
2024-December-04
CVE IDs: 
CVE-2024-13303

This module provides a field formatter for the field type 'file' called `Table of files with download all link` .

The module had vulnerabilities allowing a user to download files they normally should not be able to download.

Pages

Subscribe with RSS Subscribe to Security advisories