Session Cache API - Critical - Multiple vulnerabilities - DRUPAL-SA-CONTRIB-2017-065

Better field descriptions - Critical - XSS - SA-CONTRIB-2017-064

Relation - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-063

services_views - Unsupported - SA-CONTRIB-2017-062

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-062
  • Project: services_views (third-party module)
  • Date: 2-Aug-2017

ajax_facets - Unsupported - SA-CONTRIB-2017-061

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-061
  • Project: ajax_facets (third-party module)
  • Date: 2-Aug-2017

baidu_analytics - Unsupported - SA-CONTRIB-2017-060

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-060
  • Project: baidu_analytics (third-party module)
  • Date: 2-Aug-2017

html_title - Unsupported - SA-CONTRIB-2017-059

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-059
  • Project: html_title (third-party module)
  • Date: 2-Aug-2017

Alinks - Moderately Critical -Access bypass - SA-CONTRIB-2017-058

DrupalChat - Critical - Multiple vulnerabilities - SA-CONTRIB-2017-057

OAuth - Critical - Access Bypass - SA-CONTRIB-2017-056

Services - Critical - SQL Injection - SA-CONTRIB-2017-054

Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-003

Drupal 8.3.4 and Drupal 7.56 are maintenance releases which contain fixes for security vulnerabilities.

Search 404 - Moderately Critical - Cross Site Scripting - SA-CONTRIB-2017-053

LDAP - Critical - Data Injection - SA-CONTRIB-2017-052

Site Verify - Moderately Critical - Cross Site Scripting - SA-CONTRIB-2017-051

Custom Landing Page Builder - Unsupported - SA-CONTRIB-2017-050

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-050
  • Project: landing_page (third-party module)
  • Date: 24-May-2017

Bootstrap - Critical - Information Disclosure - SA-CONTRIB-2017-048

DRD Agent - Critical - Multiple vulnerabilities - SA-CONTRIB-2017-047

Drupal Remote Dashboard - Critical - Weak encryption keys - SA-CONTRIB-2017-046

Media - Moderately Critical - Multiple vulnerabilities - SA-CONTRIB-2017-044

shib_auth Moderately Critical - Multiple vulnerabilities - SA-CONTRIB-2017-043

Drupal Core - Critical - Access Bypass - SA-CORE-2017-002

Drupal 8 core upcoming critical release - PSA-2017-001

Date: 
2017-April-17
  • Advisory ID: DRUPAL-PSA-2017-001
  • Project: Drupal core
  • Version: 8.x
  • Date: 2017-Apr-17

Media - Critical - 1.x branch unsupported - SA-CONTRIB-2017-042

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-042
  • Project: Media (third-party module)
  • Date: 12-Apr-2017

Open Atrium - Moderately critical - Information Disclosure - SA-CONTRIB-2017-041

@Base - Critical - Unsupported - SA-CONTRIB-2017-040

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-040
  • Project: @Base (third-party module)
  • Date: 2017-April-12

References - Unsupported - SA-CONTRIB-2017-38

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-38
  • Project: References (third-party module)
  • Date: 12-Apr-2017

Filemaker Form - Critical - Unsupported - SA-CONTRIB-2017-37

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-37
  • Project: Filemaker Form (third-party module)
  • Date: 12-Apr-2017

Legal - Critical - Unsupported - SA-CONTRIB-2017-36

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-36
  • Project: Legal (third-party module)
  • Date: 12-Apr-2017

Book access - Critical - Unsupported - SA-CONTRIB-2017-35

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-35
  • Project: Book access (third-party module)
  • Date: 12-April-2017

Auto Login URL - Less Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-034

Office Hours - Moderately Critical - Cross Site Scripting - DRUPAL-SA-CONTRIB-2017-032

Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-001

Drupal 8.2.7, a maintenance release which contains fixes for security vulnerabilities, is now available for download.

Private - Critical - Access bypass - DRUPAL-SA-CONTRIB-2017-031

PRLP - Critical - Access Bypass and Privilege Escalation - SA-CONTRIB-2017-030

Services - Highly Critical - Arbitrary Code Execution - SA-CONTRIB-2017-029

Breakpoint Panels - Critical - Unsupported - SA-CONTRIB-2017-028

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-028
  • Project: breakpoint panels (third-party module)
  • Version: 7.x
  • Date: 2017-March-01

AES - Critical - Unsupported - SA-CONTRIB-2017-027

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-027
  • Project: AES encryption (third-party module)
  • Version: 7.x, 8.x
  • Date: 2017-March-01

Location Map - Moderately Critical - Multiple vulnerabilities - SA-CONTRIB-2017-026

Remember Me - Critical - Unsupported - SA-CONTRIB-2017-025

  • Advisory ID: DRUPAL-SA-CONTRIB-2017-025
  • Project: Remember Me (third-party module)
  • Version: 7.x
  • Date: 2017-March-01

DownloadFile - Critical - Unsupported - SA-CONTRIB-2017-023

Unpublished 404 - Critical - Access bypass - SA-CONTRIB-2017-021

Views - Moderately Critical - Access Bypass - SA-CONTRIB-2017-022

Pages

Subscribe with RSS Subscribe to Security advisories