Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Kategorien ›

Drupal Security

Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094

Drupal Contrib Security - 5 August, 2026 - 19:59
Project: Entity BrowserDate: 2026-August-05Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross site scriptingAffected versions: <2.16.0CVE IDs: CVE-2026-18986Description: 

The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.

The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.

Solution: 

Install the latest version:

  • If you use the Entity Browser module, upgrade to Entity Browser 8.x-2.16
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Julian Pustkuchen (anybody)
  • Sascha Grossenbacher (berdir)
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093

Drupal Contrib Security - 5 August, 2026 - 19:58
Project: Edit in-place fieldDate: 2026-August-05Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.1.1CVE IDs: CVE-2026-18985Description: 

This module provides formatters to allow in-place editing in a View or other display (full content, teaser...).

The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission".

Solution: 

Install the latest version:

  • If you use the Edit in-place field module for Drupal, upgrade to 2.1.1
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Bálint Nagy (nagy.balint)
Coordinated By: 
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
Kategorien: Drupal Security

Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092

Drupal Contrib Security - 29 Juli, 2026 - 19:12
Project: Powerful SurveysDate: 2026-July-29Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-18261Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091

Drupal Contrib Security - 29 Juli, 2026 - 19:11
Project: Disable Login PageDate: 2026-July-29Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-18260Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

Drupal Contrib Security - 29 Juli, 2026 - 19:08
Project: Token Content AccessDate: 2026-July-29Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <3.1.2CVE IDs: CVE-2026-18259Description: 

The Token Content Access module enables site administrators to provide access to content using access tokens.

The module does not sufficiently protect access token comparison in some cases. This could allow a persistent attacker to use a timing attack to guess a valid access token and bypass access restrictions for content protected by this module.

This vulnerability is mitigated by the fact that an attacker must know or discover a URL for content protected by Token Content Access, and exploiting the issue requires measuring timing differences in token comparison responses.

Solution: 

Install the latest version:

  • If you use the Token Content Access module for Drupal 10.x/11.x, upgrade to Token Content Access 3.1.2
Reported By: 
  • Robin (robincs)
Fixed By: 
  • Kyrylo Loboda (lobodakyrylo)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089

Drupal Contrib Security - 22 Juli, 2026 - 20:02
Project: Development EnvironmentDate: 2026-July-22Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-15088Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088

Drupal Contrib Security - 22 Juli, 2026 - 20:01
Project: PhotoSwipe - Responsive JavaScript Modal Image GalleryDate: 2026-July-22Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <3.2.0CVE IDs: CVE-2026-16645Description: 

The Photoswipe Drupal module provides integration for the widely used PhotoSwipe lightbox library to display / zoom images in lightbox galleries using the provided image formatters.

The module didn't sufficiently check access permissions, when viewing an image using the photoswipe image gallery display formatter, in versions < 3.0.4 (Drupal 8) or < 3.2.0 (Drupal 9 / Drupal 10).

This vulnerability is mitigated by the fact that it only affects sites limiting access to the images shown in photoswipe (the most common use case for photoswipe lightboxes public images).

Solution: 

Drupal 8 compatible version (3.0x.): Update to version 3.0.4 of the Photoswipe module.
Drupal 9 / Drupal 10 compatible version (3.1.x / 3.2.x): Ensure you're using version 3.2.0 or higher. 3.1.x is deprecated and should not be used anymore.

Reported By: 
  • Aleksi Peebles (aleksip)
Fixed By: 
  • Aleksi Peebles (aleksip)
  • Julian Pustkuchen (anybody)
  • Joshua Sedler (grevil)
Coordinated By: 
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Drupal Contrib Security - 22 Juli, 2026 - 20:00
Project: Webform RESTDate: 2026-July-22Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <4.1.0CVE IDs: CVE-2026-16644Description: 

This module enables you to retrieve and submit webform submissions via REST endpoints.

The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Solution: 

Install the latest version:

  • If you use the Webform Rest module for Drupal 8.x, upgrade to Webform Rest 4.1.0
  • Version 4.2.0 already has the fix included so no action needed if you use that version
Reported By: 
  • Giuseppe (giuseppe87)
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Giuseppe (giuseppe87)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
  • Nelson Alves (nsalves)
Coordinated By: 
  • Anna Kalata (akalata) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Michael Hess (mlhess) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Security advisory coverage removed - QA Accounts - PSA-2026-07-22

Drupal PSA Security - 22 Juli, 2026 - 19:59
Date: 2026-July-22Description: 

QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.

Solution: 

Ensure qa_accounts is not enabled on any publicly available site.

Reported By: 
  • Jordan Barnes (j-barnes)
Fixed By: 
  • Jakob P (japerry)
Kategorien: Drupal Security

Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

Drupal Contrib Security - 22 Juli, 2026 - 19:59
Project: Lunr exposed filtersDate: 2026-July-22Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: Unsupported Affected versions: *CVE IDs: CVE-2026-16643Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

Drupal Contrib Security - 22 Juli, 2026 - 19:57
Project: Email Login OTPDate: 2026-July-22Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-16642Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

Drupal Contrib Security - 22 Juli, 2026 - 19:57
Project: Commerce ElavonDate: 2026-July-22Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-16641Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

Drupal Contrib Security - 22 Juli, 2026 - 19:55
Project: PanKMDate: 2026-July-22Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-16646Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

Drupal Contrib Security - 22 Juli, 2026 - 19:55
Project: Search API AutocompleteDate: 2026-July-22Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site ScriptingAffected versions: <1.12.0CVE IDs: CVE-2026-16640Description: 

This module enables you to add autocomplete suggestions for search forms created with the Search API module.

The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.

Solution: 

Install the latest version:

  • If you use the Search API Autocomplete module, upgrade to Search API Autocomplete 8.x-1.12

Another option for sites unable to update is to set display_errors: off in php.ini (or similar settings) to disable the exploit.

Reported By: 
  • Elar Lang (elarlang)
Fixed By: 
  • Thomas Seiber (drunken monkey)
  • Elar Lang (elarlang)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

Drupal Contrib Security - 22 Juli, 2026 - 19:53
Project: Internationalization Single Sign-OnDate: 2026-July-22Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.8.0CVE IDs: CVE-2026-16639Description: 

In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.

The module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.

This vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.

Solution: 

Install the latest version:

  • If you use the Internationalization Single Sign-On module upgrade to i18n_sso 8.x-1.8
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Florent Torregrosa (grimreaper)
  • Drew Webber (mcdruid) of the Drupal Security Team
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080

Drupal Contrib Security - 22 Juli, 2026 - 19:52
Project: Media FoldersDate: 2026-July-22Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross site scriptingAffected versions: <1.0.8CVE IDs: CVE-2026-16638Description: 

This module provides a better UI for managing and selecting Media entities in a folder structure.

The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.

Solution: 

Install the latest version:

  • If you use the Media Folders module, upgrade to Media Folder 1.0.8
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • João Mauricio (jmauricio)
Coordinated By: 
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012

Drupal Core Security - 15 Juli, 2026 - 21:52
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.*CVE IDs: CVE-2026-55805Description: 

The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.

This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.

Solution: 

Install the latest version:

Drupal 11

  • If you use Drupal 11.4.x, update to Drupal 11.4.4.
  • If you use Drupal 11.3.x, update to Drupal 11.3.14.
  • Drupal 11.2.x and below are end-of-life and do not receive security coverage.

Drupal 10

  • If you use Drupal 10.6.x, update to Drupal 10.6.13.
  • Drupal 10.5.x and below are end-of-life and do not receive security coverage.

Drupal 8 and Drupal 9 have both reached end-of-life.

Reported By: 
  • haii haii (hai27ii2o)
Fixed By: 
  • danielveza
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Mingsong (mingsong) provisional member of the Drupal Security Team
  • James Gilliland (neclimdul) of the Drupal Security Team
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011

Drupal Core Security - 15 Juli, 2026 - 21:51
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.2.*CVE IDs: CVE-2026-15917Description: 

Drupal core 11.2 and above integrate the HTMX JavaScript library.

Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes.

Solution: 

Install the latest version:

Drupal 11

  • If you use Drupal 11.4.x, update to Drupal 11.4.4.
  • If you use Drupal 11.3.x, update to Drupal 11.3.14.
  • Drupal 11.2.x and below are end-of-life and do not receive security coverage.

Drupal 10

  • Drupal 10 core is not affected. However, certain contributed modules may be affected, so a Drupal 10.6 fix is included as hardening.

Drupal 8 and Drupal 9 have both reached end-of-life.

Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Shawn Duncan (fathershawn)
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • catch (catch) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010

Drupal Core Security - 15 Juli, 2026 - 21:50
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Information disclosureAffected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.*CVE IDs: CVE-2026-15916Description: 

The Image module allows you to define and configure image fields.

The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private://.

This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images.

Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12)). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings.

Solution: 

Install the latest version:

Drupal 11

  • If you use Drupal 11.4.x, update to Drupal 11.4.4.
  • If you use Drupal 11.3.x, update to Drupal 11.3.14.
  • Drupal 11.2.x and below are end-of-life and do not receive security coverage.

Drupal 10

  • If you use Drupal 10.6.x, update to Drupal 10.6.13.
  • Drupal 10.5.x and below are end-of-life and do not receive security coverage.

Drupal 8 and Drupal 9 have both reached end-of-life.

Reported By: 
  • offensive-ai
Fixed By: 
  • Benji Fisher (benjifisher) of the Drupal Security Team
  • Kim Pepper (kim.pepper)
  • Mohit Aghera (mohit_aghera)
Coordinated By: 
  • Benji Fisher (benjifisher) of the Drupal Security Team
  • catch (catch) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079

Drupal Contrib Security - 8 Juli, 2026 - 19:20
Project: Commerce guest registrationDate: 2026-July-08Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-15089Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it.

To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

You may also find that the feature to register guests in commerce core matches the feature of this module. Read more documentation on enabling account registration in checkout.

Kategorien: Drupal Security
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
  • Ich brauche dringen Hilfe zu Updates oder ggf. wwie geht Composer?
  • Dynamische Ansicht von Seiteninhalt (als Tabelle?)
  • Vergabe von Berechtigungen für bestimmte Rollen; mir fehlt der Haken bzw. das „Veröffentlicht“
  • Medien und andere Daten mit Feeds von Drupal 7 auf Drupal 10 migrieren
  • Rolle erstellen nicht zu finden
  • für drupal11 ein Slider Modul
Weiter

Neue Kommentare

  • Gefunden
    vor 6 Wochen 2 Tagen
  • Vielen Dank für die ausführlichen Hinweise...
    vor 6 Wochen 6 Tagen
  • Mögliche Ursachen und nächste Schritte
    vor 6 Wochen 6 Tagen
  • Was für einen Server benutzt
    vor 9 Wochen 2 Tagen
  • Wenn die Subdomain auf
    vor 9 Wochen 4 Tagen
  • ordnerstruktur
    vor 9 Wochen 5 Tagen
  • Die Subdomain muß auf den
    vor 10 Wochen 10 Stunden
  • Verwende doch das Tag dafür,
    vor 13 Wochen 2 Tagen
  • Guckst du hier: step by step
    vor 13 Wochen 1 Tag
  • Guckst du hier: step by step
    vor 13 Wochen 1 Tag

Statistik

Beiträge im Forum: 250294
Registrierte User: 20536

Neue User:

  • 888sportrofs
  • DanielAltek
  • HilipPet

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 26 Gäste online.

Drupal Security

  • Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094
  • Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093
  • Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092
  • Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091
  • Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association