Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099

Date: 
2026-August-12
CVE IDs: 
CVE-2026-73477

This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance.

The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant for node tabs and block plugins, and performed no access check for reusable custom blocks. Content that should have been denied was therefore rendered — for example, an unpublished node or unpublished reusable custom block could be shown to users without permission to view it.

External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098

Date: 
2026-August-12
CVE IDs: 
CVE-2026-73476

This module enables you to authenticate Drupal users against external identity providers.

The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database collation configurations.

This vulnerability is minimally mitigated by the fact that it affects only sites using impacted MySQL or MariaDB collation settings for the module’s authentication mapping storage. Affected collations are quite common so all sites are encouraged to upgrade.

Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097

Date: 
2026-August-12
CVE IDs: 
CVE-2026-73474

This module enables you to share content between sites in a hub - subscriber model.

Certain inputs were not sufficiently validated, allowing an attacker to achieve server-side request forgery attacks.

Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096

Date: 
2026-August-12
CVE IDs: 
CVE-2026-73478

This module enables you to view the differences between revisions on any entity type.

The module doesn't sufficiently restrict access to non-node entity revision diffs.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to view the entity.

Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095

Date: 
2026-August-12
CVE IDs: 
CVE-2026-73475

This module enables you to pay for Commerce transactions using Paypal.

The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment.

This vulnerability only affects sites using the Payflow Link payment gateway.

Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094

Date: 
2026-August-05
CVE IDs: 
CVE-2026-18986

The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.

The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.

Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093

Date: 
2026-August-05
CVE IDs: 
CVE-2026-18985

This module provides formatters to allow in-place editing in a View or other display (full content, teaser...).

The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission".

Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092

Date: 
2026-July-29
CVE IDs: 
CVE-2026-18261

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091

Date: 
2026-July-29
CVE IDs: 
CVE-2026-18260

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

Date: 
2026-July-29
CVE IDs: 
CVE-2026-18259

The Token Content Access module enables site administrators to provide access to content using access tokens.

The module does not sufficiently protect access token comparison in some cases. This could allow a persistent attacker to use a timing attack to guess a valid access token and bypass access restrictions for content protected by this module.

Pages

Subscribe with RSS Subscribe to Security advisories