Newsfeed-Generator
Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration.
When the "Allow HTML description" option is enabled, slide descriptions are rendered using the raw stored field value instead of the field's rendered output. This bypasses Drupal's text format filtering and output sanitization mechanisms.
This vulnerability affects sites that use a formatted text field as the carousel description source and have enabled the "Allow HTML description" option.
Solution:Upgrade to the latest version:
- If you are using Diba carousel slider 3.1.x, upgrade to Diba carousel slider 3.1.0.
- If you are using Diba carousel slider 3.0.x, upgrade to Diba carousel slider 3.0.2.
If you are unable to upgrade immediately, disable the "Allow HTML description" option in affected carousel blocks until the update can be applied.
Reported By: Fixed By: Coordinated By:- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.
The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint.
This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.
Solution:Install the latest version:
- Upgrade to Smart Content 3.2.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
This module lets a frontend scanner post CSS-usage measurements to the site so admin reports can show real-page statistics.
This module doesn't sufficiently protect the /css-usage-analyzer/save endpoint against forged or repeated submissions.
Solution:Install the latest version:
- Upgrade to CSS Usage Analyzer 1.0.2.
- Greg Knaddison (greggles) of the Drupal Security Team
- Marcus Johansson (marcus_johansson)
- Zeeshaan khann (zeeshan_khan)
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
This module enables you to combine multiple image styles into a single image derivative.
The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.
Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.
This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.
Solution:Install the latest version:
- If you use the Combined image style module, upgrade to Combined image style 1.0.7.
- Sven Decabooter (svendecabooter)
- Swan Kalata (akalata) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
This module enables you to use AI to fill in or replace text in CKEditor.
The module doesn't sufficiently mitigate Twig template injections in certain AI CKEditor rules, making it possible to use Twig functions to extract certain confidential system data.
Solution:Install the latest version:
- If you use the AI CKEditor module, upgrade to AI CKEditor 1.4.3.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform REST - Less critical - Access bypass - SA-CONTRIB-2026-186
This module enables you to retrieve and submit webforms via REST.
The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.
Solution:Install the latest version:
- Upgrade to Webform REST 4.2.1. The 4.1.x branch is no longer supported.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Editoria11y Accessibility Checker - Moderately critical - Access bypass - SA-CONTRIB-2026-185
This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.
The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.
Solution:If you use the Editoria11y module, update the module and review permissions.
- If you use the Editoria11y module version 2.2.x, upgrade to editoria11y 2.2.23.
- If you use the Editoria11y module version 3.0.x, upgrade to editoria11y 3.0.9.
Review permissions: Make sure anonymous or untrusted authenticated users have not been given permission to use the checker. The permission is labeled as:
- View Editoria11y checker up to and including 2.2.22/3.0.8, and
- Run Editoria11y checker and report results with 2.2.23/3.0.9.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Tawk.to - Live chat application - Critical - Cross Site Request Forgery - SA-CONTRIB-2026-184
This module provides integration of the tawk.to live chat for Drupal sites.
The module does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.
Solution:Install the latest version:
- Upgrade to tawk.to 3.0.4.
After updating, clear the Drupal cache.
Reported By: Fixed By: Coordinated By:- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183
This module enables sites to block access for the administrative user account (user 1) or users with the administrator role.
The module does not sufficiently enforce these access restrictions across all supported authentication mechanisms. As a result, a blocked administrative user may still be able to authenticate through certain alternative authentication methods.
This vulnerability is mitigated by the fact that an attacker must possess valid credentials for a user with the administrator role, and must authenticate using a less commonly used authentication mechanism.
Solution:Install the latest version:
- If you use the Stop Administrator Login module, upgrade to Stop Administrator Login 8.x-1.6
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182
This module enables you to add an extra authentication layer to the API.
The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.
Solution:Install the latest version:
- Upgrade to REST & JSON API Authentication 3.2.0.
- Drew Webber (mcdruid) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- purva_shende
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Heine Deelstra (heine) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
CookieCuttr - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-181
This module enables you to provide information and options about cookie usage.
The module does not sufficiently filter input submitted through the Cookiecuttr administration form. This could allow specially crafted values to be stored and later rendered without adequate sanitization, resulting in a cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission administer cookiecuttr.
Solution:Install the latest version:
- Upgrade to cookiecuttr 2.0.3.
- Swan Kalata (akalata) of the Drupal Security Team
- Marcus Johansson (marcus_johansson)
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Mermaid Diagram Field - Moderately critical - Access bypass - SA-CONTRIB-2026-180
This module enables you to add mermaid diagram that displays either inline on an entity or optionally in a modal.
The module doesn't sufficiently respect default revision behavior and does not properly limit access to the modal content.
This vulnerability is mitigated by the fact that an attacker must have the modal display option enabled for the field, or otherwise know the route of the modal and entity ID.
Solution:Install the latest version:
- If you use the Mermaid Diagram Field module, upgrade to Mermaid Diagram Field 1.0.10.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Commerce Decoupled Checkout - Moderately critical - Access bypass - SA-CONTRIB-2026-179
This module enables REST endpoints for a decoupled Commerce experience which allow for remote order creation.
The module doesn't sufficiently sanitize order data passed into the order creation endpoint, which allows for potentially unsafe order properties to be set on an order.
Solution:Install the latest version of the module:
- Update to Commerce Decoupled Checkout 8.x-1.8.
The standard order fields type, email, store, and order_items remain accepted by default.
Sites submitting additional custom order fields must explicitly enable them at /admin/commerce/config/decoupled-checkout. Requests containing fields outside this allowlist will be rejected.
Run database updates and configure the required customer-writable fields before resuming checkout.
Reported By: Fixed By: Coordinated By:- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Project Browser - Critical - Cross-site request forgery - SA-CONTRIB-2026-178
The Project Browser module enables you to apply recipes and enable modules from the web user interface.
The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF).
Solution:Install the latest version:
- If you use the 2.1.x branch, upgrade to Project Browser 2.1.5.
- If you use the 2.0.x branch, upgrade to Project Browser 2.0.3.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Cloud - Critical - Remote code execution - SA-CONTRIB-2026-177
The Cloud module enables users to manage cloud resources through Drupal.
The module does not sufficiently sanitize user-controlled Git branch and repository URL values before passing them to shell commands in the Kubernetes integration. This vulnerability allows an attacker to execute arbitrary operating-system commands as the web-server user.
This vulnerability is mitigated by the fact that the Kubernetes submodule must be enabled and configured, Git must be available on the server, and an attacker must have permission to add or edit cloud server templates. Exploiting the clone path additionally requires the "launch cloud server template" permission, or the "launch approved cloud server template" permission when using the approved-template flow.
Solution:Install the latest version:
- If you use Cloud 7.x, upgrade to Cloud 7.0.1.
- Drew Webber (mcdruid) of the Drupal Security Team
- AI Yas (ai_yas)
- Drew Webber (mcdruid) of the Drupal Security Team
- Yas Naoi (yas)
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176
The Cloud module enables users to manage cloud infrastructure through Drupal.
The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.
Solution:If you use Cloud, install the latest version and configure certificates appropriately:
- If you use the 7.0.0 branch, update to 7.0.1.
The update enables TLS certificate verification for Kubernetes and VMware connections. Sites using a private certificate authority must configure the CA certificate path for the affected connection or ensure that the issuing CA is trusted by the PHP runtime. Run the Drupal database updates and rebuild caches after upgrading.
Reported By: Fixed By: Coordinated By:- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
The Webform module allows site builders to create forms, collect submissions, and render submitted values in configurable formats.
Webform does not sufficiently exclude certain format templates from token replacement. This can allow an attacker to submit data that is evaluated as template code when a submission is rendered. Depending on the site configuration and enabled modules, this may lead to information disclosure, stored cross-site scripting, or remote code execution.
This vulnerability is mitigated by the fact that an affected webform must be configured with a custom multiple-value item format that includes submission-value tokens. Some impacts may also depend on additional enabled modules or site-specific configuration.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Webform did not sufficiently guard user-specific access rules against a malformed saved configuration. Under certain site-specific conditions, an access rule intended to grant submission access only to selected user accounts could also grant access to anonymous users.
This vulnerability is mitigated by the fact that the bypass depends on malformed saved access-rule configuration.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Less critical - Access bypass - SA-CONTRIB-2026-173
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module did not sufficiently restrict access to certain submission view modes. Under certain conditions, a user who can view a submission could access a more permissive view mode and see fields that would otherwise be restricted.
This vulnerability is mitigated by the fact that an attacker must already have access to view the affected submission.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Form submissions may include uploaded files.
The module does not sufficiently force certain uploaded file types to download when served. Under certain site configurations, a file uploaded through a webform could be rendered inline by a browser, resulting in a cross-site scripting vulnerability.
This vulnerability is mitigated by the fact that a user with permission to create or edit webforms must configure the form to allow the affected file extensions, and a user must specifically open the uploaded file.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- nächste Seite ›
- letzte Seite »

Neue Kommentare
vor 2 Wochen 23 Stunden
vor 2 Wochen 3 Tagen
vor 2 Wochen 5 Tagen
vor 3 Wochen 1 Tag
vor 3 Wochen 1 Tag
vor 3 Wochen 1 Tag
vor 3 Wochen 1 Tag
vor 3 Wochen 4 Tagen
vor 3 Wochen 5 Tagen
vor 3 Wochen 5 Tagen