Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite ›

Newsfeed-Generator

Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191

Drupal Contrib Security - 23 September, 2026 - 19:24
Project: Diba carousel sliderProject machine name: diba_carouselDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross Site Scripting (XSS)Affected versions: <3.0.2CVE IDs: CVE-2026-96382Description: 

The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration.

When the "Allow HTML description" option is enabled, slide descriptions are rendered using the raw stored field value instead of the field's rendered output. This bypasses Drupal's text format filtering and output sanitization mechanisms.

This vulnerability affects sites that use a formatted text field as the carousel description source and have enabled the "Allow HTML description" option.

Solution: 

Upgrade to the latest version:

  • If you are using Diba carousel slider 3.1.x, upgrade to Diba carousel slider 3.1.0.
  • If you are using Diba carousel slider 3.0.x, upgrade to Diba carousel slider 3.0.2.

If you are unable to upgrade immediately, disable the "Allow HTML description" option in affected carousel blocks until the update can be applied.

Reported By: 
  • Kalle Kipinä (kekkis)
Fixed By: 
  • Oriol Roselló Castells (oriol_e9g)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190

Drupal Contrib Security - 23 September, 2026 - 19:23
Project: Smart ContentProject machine name: smart_contentDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <3.2.1CVE IDs: CVE-2026-96386Description: 

This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.

The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint.

This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.

Solution: 

Install the latest version:

  • Upgrade to Smart Content 3.2.1.
Reported By: 
  • Tin Nguyen Huu (s4m0y3d)
Fixed By: 
  • Michael Lander (michaellander)
  • Tin Nguyen Huu (s4m0y3d)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189

Drupal Contrib Security - 23 September, 2026 - 19:22
Project: CSS Usage AnalyzerProject machine name: css_usage_analyzerDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Improper access controlAffected versions: >=1.0.0 <1.0.2CVE IDs: CVE-2026-96380Description: 

This module lets a frontend scanner post CSS-usage measurements to the site so admin reports can show real-page statistics.

This module doesn't sufficiently protect the /css-usage-analyzer/save endpoint against forged or repeated submissions.

Solution: 

Install the latest version:

  • Upgrade to CSS Usage Analyzer 1.0.2.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Marcus Johansson (marcus_johansson)
  • Zeeshaan khann (zeeshan_khan)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188

Drupal Contrib Security - 23 September, 2026 - 19:21
Project: Combined image styleProject machine name: combined_image_styleDate: 2026-September-23Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:AllVulnerability: Improper access controlAffected versions: <1.0.7CVE IDs: CVE-2026-96377Description: 

This module enables you to combine multiple image styles into a single image derivative.

The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.

Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.

This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.

Solution: 

Install the latest version:

  • If you use the Combined image style module, upgrade to Combined image style 1.0.7.
Reported By: 
  • Sven Decabooter (svendecabooter)
Fixed By: 
  • Sven Decabooter (svendecabooter)
  • Swan Kalata (akalata) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187

Drupal Contrib Security - 23 September, 2026 - 19:20
Project: AI CKEditorProject machine name: ai_ckeditorDate: 2026-September-23Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Code execution via Twig templatesAffected versions: <1.4.3CVE IDs: CVE-2026-96392Description: 

This module enables you to use AI to fill in or replace text in CKEditor.

The module doesn't sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.

Solution: 

Install the latest version:

  • If you use the AI CKEditor module, upgrade to AI CKEditor 1.4.3.
Reported By: 
  • Stef Rouschop (stefro)
Fixed By: 
  • Artem Dmitriiev (a.dmitriiev)
  • Marcus Johansson (marcus_johansson)
  • Stef Rouschop (stefro)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform REST - Less critical - Access bypass - SA-CONTRIB-2026-186

Drupal Contrib Security - 23 September, 2026 - 19:19
Project: Webform RESTProject machine name: webform_restDate: 2026-September-23Security risk: Less critical 9 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <4.2.1CVE IDs: CVE-2026-96391Description: 

This module enables you to retrieve and submit webforms via REST.

The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.

Solution: 

Install the latest version:

  • Upgrade to Webform REST 4.2.1. The 4.1.x branch is no longer supported.
Reported By: 
  • Lauri (laurii)
Fixed By: 
  • Adam Bramley (acbramley)
  • Miguel Ferreira (miguelpamferreira)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Editoria11y Accessibility Checker - Moderately critical - Access bypass - SA-CONTRIB-2026-185

Drupal Contrib Security - 23 September, 2026 - 19:18
Project: Editoria11y Accessibility CheckerProject machine name: editoria11yDate: 2026-September-23Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:User/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.2.23 || >=3.0.0 <3.0.9CVE IDs: CVE-2026-96390Description: 

This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.

The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.

Solution: 

If you use the Editoria11y module, update the module and review permissions.

  • If you use the Editoria11y module version 2.2.x, upgrade to editoria11y 2.2.23.
  • If you use the Editoria11y module version 3.0.x, upgrade to editoria11y 3.0.9.

Review permissions: Make sure anonymous or untrusted authenticated users have not been given permission to use the checker. The permission is labeled as:

  • View Editoria11y checker up to and including 2.2.22/3.0.8, and
  • Run Editoria11y checker and report results with 2.2.23/3.0.9.
Reported By: 
  • Maksim Hayder (tr_jan)
Fixed By: 
  • Brian Osborne (bkosborne)
  • John Jameson (itmaybejj)
  • Jason Partyka (partyka)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Tawk.to - Live chat application - Critical - Cross Site Request Forgery - SA-CONTRIB-2026-184

Drupal Contrib Security - 23 September, 2026 - 19:14
Project: Tawk.to - Live chat applicationProject machine name: tawk_toDate: 2026-September-23Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross Site Request ForgeryAffected versions: <3.0.4CVE IDs: CVE-2026-96388Description: 

This module provides integration of the tawk.to live chat for Drupal sites.

The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.

Solution: 

Install the latest version:

  • Upgrade to tawk.to 3.0.4.

After updating, clear the Drupal cache.

Reported By: 
  • Tin Nguyen Huu (s4m0y3d)
Fixed By: 
  • Andriy Khomych (andriy khomych)
  • Tin Nguyen Huu (s4m0y3d)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183

Drupal Contrib Security - 23 September, 2026 - 19:11
Project: Stop administrator loginProject machine name: stop_adminDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: >=1.0 <1.6CVE IDs: CVE-2026-96387Description: 

This module enables sites to block access for the administrative user account (user 1) or users with the administrator role.

The module does not sufficiently enforce these access restrictions across all supported authentication mechanisms. As a result, a blocked administrative user may still be able to authenticate through certain alternative authentication methods.

This vulnerability is mitigated by the fact that an attacker must possess valid credentials for a user with the administrator role, and must authenticate using a less commonly used authentication mechanism.

Solution: 

Install the latest version:

  • If you use the Stop Administrator Login module, upgrade to Stop Administrator Login 8.x-1.6
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182

Drupal Contrib Security - 23 September, 2026 - 19:10
Project: REST & JSON API Authentication for DrupalProject machine name: rest_api_authenticationDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <3.2.0CVE IDs: CVE-2026-96385Description: 

This module enables you to add an extra authentication layer to the API.

The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.

Solution: 

Install the latest version:

  • Upgrade to REST & JSON API Authentication 3.2.0.
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
  • purva_shende
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Heine Deelstra (heine) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

CookieCuttr - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-181

Drupal Contrib Security - 23 September, 2026 - 19:08
Project: CookieCuttrProject machine name: cookiecuttrDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: >=2.0.0 <2.0.3CVE IDs: CVE-2026-96379Description: 

This module enables you to provide information and options about cookie usage.

The module does not sufficiently filter input submitted through the Cookiecuttr administration form. This could allow specially crafted values to be stored and later rendered without adequate sanitization, resulting in a cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission administer cookiecuttr.

Solution: 

Install the latest version:

  • Upgrade to cookiecuttr 2.0.3.
Reported By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Malcolm Young (malcomio)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Mermaid Diagram Field - Moderately critical - Access bypass - SA-CONTRIB-2026-180

Drupal Contrib Security - 23 September, 2026 - 19:07
Project: Mermaid Diagram FieldProject machine name: mermaid_diagram_fieldDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: >=1.0.4 <1.0.9CVE IDs: CVE-2026-96384Description: 

This module enables you to add mermaid diagram that displays either inline on an entity or optionally in a modal.

The module doesn't sufficiently respect default revision behavior and does not properly limit access to the modal content.

This vulnerability is mitigated by the fact that an attacker must have the modal display option enabled for the field, or otherwise know the route of the modal and entity ID.

Solution: 

Install the latest version:

  • If you use the Mermaid Diagram Field module, upgrade to Mermaid Diagram Field 1.0.10.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Steve Wirt (swirt)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Commerce Decoupled Checkout - Moderately critical - Access bypass - SA-CONTRIB-2026-179

Drupal Contrib Security - 23 September, 2026 - 19:06
Project: Commerce Decoupled CheckoutProject machine name: commerce_decoupled_checkoutDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: >=1.0.0 <1.8.0CVE IDs: CVE-2026-96378Description: 

This module enables REST endpoints for a decoupled Commerce experience which allow for remote order creation.

The module doesn't sufficiently sanitize order data passed into the order creation endpoint, which allows for potentially unsafe order properties to be set on an order.

Solution: 

Install the latest version of the module:

  • Update to Commerce Decoupled Checkout 8.x-1.8.

The standard order fields type, email, store, and order_items remain accepted by default.

Sites submitting additional custom order fields must explicitly enable them at /admin/commerce/config/decoupled-checkout. Requests containing fields outside this allowlist will be rejected.

Run database updates and configure the required customer-writable fields before resuming checkout.

Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Leo Pitt (leo pitt)
  • Marcus Johansson (marcus_johansson)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Project Browser - Critical - Cross-site request forgery - SA-CONTRIB-2026-178

Drupal Contrib Security - 23 September, 2026 - 18:53
Project: Project BrowserProject machine name: project_browserDate: 2026-September-23Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site request forgeryAffected versions: <2.0.3 || >=2.1.0 <2.1.5CVE IDs: CVE-2026-96374Description: 

The Project Browser module enables you to apply recipes and enable modules from the web user interface.

The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF).

Solution: 

Install the latest version:

  • If you use the 2.1.x branch, upgrade to Project Browser 2.1.5.
  • If you use the 2.0.x branch, upgrade to Project Browser 2.0.3.
Reported By: 
  • Tin Nguyen Huu (s4m0y3d)
Fixed By: 
  • Chris Wells (chrisfromredfin)
  • Tin Nguyen Huu (s4m0y3d)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Cloud - Critical - Remote code execution - SA-CONTRIB-2026-177

Drupal Contrib Security - 23 September, 2026 - 18:51
Project: CloudProject machine name: cloudDate: 2026-September-23Security risk: Critical 15 ∕ 25 AC:Basic/A:Admin/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Remote code executionAffected versions: <7.0.1CVE IDs: CVE-2026-96376Description: 

The Cloud module enables users to manage cloud resources through Drupal.

The module does not sufficiently sanitize user-controlled Git branch and repository URL values before passing them to shell commands in the Kubernetes integration. This vulnerability allows an attacker to execute arbitrary operating-system commands as the web-server user.

This vulnerability is mitigated by the fact that the Kubernetes submodule must be enabled and configured, Git must be available on the server, and an attacker must have permission to add or edit cloud server templates. Exploiting the clone path additionally requires the "launch cloud server template" permission, or the "launch approved cloud server template" permission when using the approved-template flow.

Solution: 

Install the latest version:

  • If you use Cloud 7.x, upgrade to Cloud 7.0.1.
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • AI Yas (ai_yas)
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Yas Naoi (yas)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176

Drupal Contrib Security - 23 September, 2026 - 18:50
Project: CloudProject machine name: cloudDate: 2026-September-23Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Remote code executionAffected versions: <7.0.1CVE IDs: CVE-2026-96375Description: 

The Cloud module enables users to manage cloud infrastructure through Drupal.

The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.

Solution: 

If you use Cloud, install the latest version and configure certificates appropriately:

  • If you use the 7.0.0 branch, update to 7.0.1.

The update enables TLS certificate verification for Kubernetes and VMware connections. Sites using a private certificate authority must configure the CA certificate path for the affected connection or ensure that the issuing CA is trusted by the PHP runtime. Run the Drupal database updates and rebuild caches after upgrading.

Reported By: 
  • Kalle Kipinä (kekkis)
Fixed By: 
  • AI Yas (ai_yas)
  • baldwinlouie
  • Yas Naoi (yas)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175

Drupal Contrib Security - 23 September, 2026 - 18:27
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Critical 18 ∕ 25 AC:Basic/A:None/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Remote Code ExecutionAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96355Description: 

The Webform module allows site builders to create forms, collect submissions, and render submitted values in configurable formats.

Webform does not sufficiently exclude certain format templates from token replacement. This can allow an attacker to submit data that is evaluated as template code when a submission is rendered. Depending on the site configuration and enabled modules, this may lead to information disclosure, stored cross-site scripting, or remote code execution.

This vulnerability is mitigated by the fact that an affected webform must be configured with a custom multiple-value item format that includes submission-value tokens. Some impacts may also depend on additional enabled modules or site-specific configuration.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Michael Maturi (michaelmaturi)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174

Drupal Contrib Security - 23 September, 2026 - 18:27
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96356Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Webform did not sufficiently guard user-specific access rules against a malformed saved configuration. Under certain site-specific conditions, an access rule intended to grant submission access only to selected user accounts could also grant access to anonymous users.

This vulnerability is mitigated by the fact that the bypass depends on malformed saved access-rule configuration.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Adam Bramley (acbramley)
  • enyug
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Less critical - Access bypass - SA-CONTRIB-2026-173

Drupal Contrib Security - 23 September, 2026 - 18:27
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Less critical 9 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96398Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module did not sufficiently restrict access to certain submission view modes. Under certain conditions, a user who can view a submission could access a more permissive view mode and see fields that would otherwise be restricted.

This vulnerability is mitigated by the fact that an attacker must already have access to view the affected submission.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Mustafa Ahmed (mustafa007)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Mustafa Ahmed (mustafa007)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172

Drupal Contrib Security - 23 September, 2026 - 18:26
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96357Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Form submissions may include uploaded files.

The module does not sufficiently force certain uploaded file types to download when served. Under certain site configurations, a file uploaded through a webform could be rendered inline by a browser, resulting in a cross-site scripting vulnerability.

This vulnerability is mitigated by the fact that a user with permission to create or edit webforms must configure the form to allow the affected file extensions, and a user must specifically open the uploaded file.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Michael Maturi (michaelmaturi)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Canvas Palette: Eine fertige Komponentenbibliothek für Drupal Canvas
  • Hilfe zu Updates oder Composer
  • Vergleich Drupal und Contao
  • [geloest] Blocks in Bootstrap nebeneinander darstellen und nicht untereinander
  • DrupalCamp Frankfurt 27-28 November 2026
  • Bitte mein Bentzerkonto löschen
  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
Weiter

Neue Kommentare

  • Danke ich werde mir die
    vor 2 Wochen 23 Stunden
  • Vielen Dank für Ihren
    vor 2 Wochen 3 Tagen
  • Composer ist sehr ratsam
    vor 2 Wochen 5 Tagen
  • Vielen Dank für den
    vor 3 Wochen 1 Tag
  • Die alten CMS Vergleiche von contentmanager.de
    vor 3 Wochen 1 Tag
  • Gut gemacht
    vor 3 Wochen 1 Tag
  • Layout Builder etc. z.B. für Landing Pages
    vor 3 Wochen 1 Tag
  • Links
    vor 3 Wochen 4 Tagen
  • Moin,wow, sehr gutes
    vor 3 Wochen 5 Tagen
  • Dass ist eine spannende
    vor 3 Wochen 5 Tagen

Statistik

Beiträge im Forum: 250316
Registrierte User: 20564

Neue User:

  • Robertspaft
  • drupalthemes
  • rofilm

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 134 Gäste online.

Drupal Security

  • Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
  • Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association