Plausible tracking - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-107

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10927

This module integrates Plausible Analytics on a site.

The module did not properly filter output in certain cases.

This vulnerability is mitigated by the fact that an attacker must have permission to add raw HTML to the website, such as an unfiltered WYSIWYG field on a public-facing comment.

JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106

Date: 
2025-September-24
CVE IDs: 
CVE-2025-10926

This module enables you to store and display JSON data using optional 3rd party libraries.

The module doesn't sufficiently filter data using some of the included field formatters leading to a Cross-site Scripting (XSS) vulnerability.

Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105

Date: 
2025-September-03
CVE IDs: 
CVE-2025-9954

This module enables you to connect a Drupal site to the Acquia DAM service, which syncs media from the third party service to the site.

The module doesn't sufficiently validate authorization to a list of DAM assets currently synced to the website creating an access bypass vulnerability.

This vulnerability is mitigated by the fact that it only impacts sites where users having the “view media” permission accessing any DAM asset is undesirable.

Owl Carousel 2 - Critical - Unsupported - SA-CONTRIB-2025-104

Date: 
2025-August-27
CVE IDs: 
CVE-2025-9554

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

API Key manager - Critical - Unsupported - SA-CONTRIB-2025-103

Date: 
2025-August-27
CVE IDs: 
CVE-2025-9553

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Synchronize composer.json With Contrib Modules - Critical - Unsupported - SA-CONTRIB-2025-102

Date: 
2025-August-27
CVE IDs: 
CVE-2025-9552

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Protected Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-101

Date: 
2025-August-27
CVE IDs: 
CVE-2025-9551

This module enables you to protect individual pages with a password.

The module doesn't limit the number of password attempts, making it vulnerable to brute force attacks.

This vulnerability is mitigated by the fact that an attacker must know the protected page's URL.

CVSS risk score (experimental) 6.3 / Medium

Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100

Date: 
2025-August-27
CVE IDs: 
CVE-2025-9550

This module enables you to to easily create and manage faceted search interfaces.

The module doesn’t sufficiently filter certain user-provided text leading to a cross site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer facets”.

CVSS risk score (experimental) 4.8 / Medium

Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099

Date: 
2025-August-27
CVE IDs: 
CVE-2025-9549

This module enables you to to easily create and manage faceted search interfaces.

The module doesn't sufficiently check access to entities when they are displayed as facets.

This vulnerability is mitigated by the fact that only sites that show facets with entity labels (like taxonomy terms) are affected, and only if some of those entities are unpublished or have other access restrictions.

CVSS risk score (experimental) 6.9 / Medium

Pages

Subscribe with RSS Subscribe to Security advisories