Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Herkunft ›

Drupal Contrib Security

Inhalt abgleichen
URL: https://www.drupal.org/security/contrib
Aktualisiert: vor 37 Minuten 5 Sekunden

Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079

8 Juli, 2026 - 19:20
Project: Commerce guest registrationDate: 2026-July-08Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-15089Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it.

To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

You may also find that the feature to register guests in commerce core matches the feature of this module. Read more documentation on enabling account registration in checkout.

Kategorien: Drupal Security

Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078

8 Juli, 2026 - 19:19
Project: Clean RESTfulDate: 2026-July-08Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-15087Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077

8 Juli, 2026 - 19:19
Project: Raw Formatter [Meta Tag Formatter]Date: 2026-July-08Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedAffected versions: *CVE IDs: CVE-2026-15086Description: 

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Solution: 

If you use this project, you should uninstall it. To take over maintainership, please read https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Kategorien: Drupal Security

AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076

8 Juli, 2026 - 19:18
Project: AI SEO/GEO AnalyzerDate: 2026-July-08Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site ScriptingAffected versions: <1.1.3CVE IDs: CVE-2026-15085Description: 

The AI SEO/GEO Analyzer module generates SEO/GEO analysis reports by sending content of an entity (including its comments) to an LLM, then converts the model's Markdown response to HTML and stores it for display to privileged users.

The generated HTML was rendered without passing through Drupal's filtering pipeline, so it relied on the LLM output being safe. Under certain circumstances a crafted prompt injection — planted in content that is included in the analysis — can cause the LLM to emit markup that results in stored Cross-site Scripting when the report is later viewed.

This vulnerability is mitigated by the fact that an attacker must be able to inject text into the content that is sent to the LLM, and that prompt injection is non-deterministic and not guaranteed to succeed on a given attempt.

Solution: 

Install the latest version:

  • If you use the AI SEO/GEO Analyzer module 1.1.x, upgrade to ai_seo 1.1.3
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Juhani Väätäjä (j-vee)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
Kategorien: Drupal Security

UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075

8 Juli, 2026 - 19:17
Project: UI Patterns (SDC in Drupal UI)Date: 2026-July-08Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross site scriptingAffected versions: >=2.0.0 <2.0.17CVE IDs: CVE-2026-15084Description: 

This module enables you to use Single Directory Components in site building (views, field formatters, blocks, layouts) and it improves the Developer Experience (DX) with SDC.

The module doesn't sufficiently sanitize the markup passed to components under certain scenarios.

This vulnerability is mitigated by the fact that an attacker must be able to create or update content rendered by UI Patterns.

Solution: 

Install the latest version:

  • If you use the UI Patterns module on version 2, upgrade to UI Patterns 2.0.17
Reported By: 
  • Hervé Donner (herved)
Fixed By: 
  • Florent Torregrosa (grimreaper)
  • Hervé Donner (herved)
  • Mikael Meulle (just_like_good_vibes)
  • Pierre Dureau (pdureau)
Coordinated By: 
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
Kategorien: Drupal Security

ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074

8 Juli, 2026 - 19:16
Project: ECA: Event - Condition - ActionDate: 2026-July-08Security risk: Less critical 8 ∕ 25 AC:Complex/A:User/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Information disclosureAffected versions: <2.1.20 || >=3.0.0 <3.0.12 || >=3.1.0 <3.1.4CVE IDs: CVE-2026-15083Description: 

The Events, Conditions, Actions (ECA) module's Render submodule enables you to build render arrays and render inline Twig templates as part of no-code ECA models.

The module doesn't sufficiently sanitize template code when rendering, which can lead to information disclosure.

This vulnerability is mitigated by the fact that a site must be running an ECA model that uses the "Render: Twig" action on a data flow.

Solution: 

Install the latest version:

  • If you use the ECA 3.1 for Drupal 10.x or 11.x, upgrade to ECA 3.1.4
  • If you use the ECA 3.0 for Drupal 10.x or 11.x, upgrade to ECA 3.0.12
  • If you use the ECA 1.2 for Drupal 10.x or 11.x, upgrade to ECA 2.1.20
Reported By: 
  • Changhai Qi (qichanghai)
Fixed By: 
  • Jürgen Haas (jurgenhaas)
Coordinated By: 
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
Kategorien: Drupal Security

Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073

8 Juli, 2026 - 19:15
Project: Siteimprove AnalyticsDate: 2026-July-08Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site ScriptingAffected versions: <2.0.1CVE IDs: CVE-2026-15082Description: 

The module doesn't sufficiently sanitize the Siteimprove Analytics identification code when inserting the JavaScript tracking code; this could be exploited to achieve Cross-Site Scripting (XSS).

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer siteimprove_analytics".

Solution: 

Install the latest version:

  • If you use the siteimprove_analytics module for Drupal verision prior 10.3, upgrade to siteimprove_analytics 2.0.1
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Bohdan Artemchuk (bohart)
  • Andriy Parkhomiuk (grask0)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072

8 Juli, 2026 - 19:14
Project: Location SelectorDate: 2026-July-08Security risk: Critical 19 ∕ 25 AC:Basic/A:None/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: SQL InjectionAffected versions: <1.3.0CVE IDs: CVE-2026-15081Description: 

The Location Selector module provides a Views filter for selecting location values.

One of the provided Views filters does not sufficiently sanitize values that may come from user input, resulting in a SQL injection vulnerability.

This vulnerability is mitigated by the fact that a View must exist that uses the affected filter and is configured to accept user input.

Solution: 

Install the latest version:

  • If you use the Location Selector module for Drupal, upgrade to Location Selector 8.x-1.3
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • handkerchief
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071

8 Juli, 2026 - 19:13
Project: Ray Enterprise TranslationDate: 2026-July-08Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Cross site request forgeryAffected versions: <4.0.4 || >=4.1.0 <4.1.4 || >=11.0.0 <11.0.4CVE IDs: CVE-2026-15080Description: 

The Lingotek Ray Enterprise Translation module provides multilingual site management.

The module fails to protect several state-changing administrative routes against Cross Site Request Forgery attacks. An attacker could trick a privileged user into visiting a crafted page that triggers actions such as updating callback settings, uploading or downloading translations, or changing translation state.

Solution: 

Install the latest version appropriate for your site

  • If you use the Ray Enterprise Translation module, upgrade to Ray Enterprise Translation 11.0.4
  • If you use the Ray Enterprise Translation module, upgrade to Ray Enterprise Translation 4.1.4
  • If you use the Ray Enterprise Translation module, upgrade to Ray Enterprise Translation 4.0.4
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Naresh Bavaskar (naresh_bavaskar)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070

8 Juli, 2026 - 19:12
Project: Login DisableDate: 2026-July-08Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.1.4CVE IDs: CVE-2026-15079Description: 

The Login Disable module prevents users from logging in to your Drupal site unless they know the secret key to add to the end of the login form page.

The module doesn't sufficiently protect the disabled login form from brute force attacks. Depending on the length of the key this could allow an attacker to use a brute force attack to bypass the protection provided by this module. The security fix blocks these attempts with flood control.

This vulnerability is mitigated by the fact that an attacker must obtain a valid username & password.

Solution: 

Install the latest version:

  • If you use the Login Disable module, upgrade to Login Disable 2.1.4
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Boris Doesborg (batigolix)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069

1 Juli, 2026 - 19:24
Project: ColorboxDate: 2026-July-01Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: < 2.1.5 || 2.2.0CVE IDs: CVE-2026-58591Description: 

The Colorbox module integrates with the Colorbox JavaScript library to display content in an overlay above the page.

The module doesn't sufficiently protect against injection of malicious JavaScript under certain scenarios.

This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.

Solution: 

Install the latest version:

  • If you use Colorbox 2.1.x, upgrade to: Colorbox 2.1.5
  • If you use Colorbox 2.2.x, upgrade to: Colorbox 2.2.1
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Paul McKibben (paulmckibben)
Coordinated By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068

1 Juli, 2026 - 19:22
Project: FlowDropDate: 2026-July-01Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.6.0CVE IDs: CVE-2026-58590Description: 

This module enables you to test and run AI-driven workflows interactively through a chat interface.

The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions).

Solution: 

Install the latest version:

  • If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0
Reported By: 
  • Aincient Labs (aincient labs)
Fixed By: 
  • Shibin Das (d34dman)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
Kategorien: Drupal Security

FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067

1 Juli, 2026 - 19:21
Project: FlowDropDate: 2026-July-01Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.6.0CVE IDs: CVE-2026-58589Description: 

This module enables you to test and run AI-driven workflows interactively through a chat interface.

The module doesn't sufficiently enforce permissions on certain endpoints. Attackers may be able to trigger workflow execution (incurring LLM spend and tool side effects) or send messages into other user's sessions.

This vulnerability is mitigated by the fact that an attacker must have the permission "View any session", which is not granted to anonymous or authenticated users by default.

Solution: 

Install the latest version:

  • If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0

Driving a session now additionally requires the "Execute session workflow" permission.

Reported By: 
  • Aincient Labs (aincient labs)
Fixed By: 
  • Shibin Das (d34dman)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
Kategorien: Drupal Security

Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066

1 Juli, 2026 - 19:21
Project: Drupal CanvasDate: 2026-July-01Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Improper validationAffected versions: <1.4.2 || >=1.5.0 <1.5.2 || >=1.6.0 <1.6.1 || >=1.7.0 <1.7.1CVE IDs: CVE-2026-58588Description: 

The Canvas module allow you to upload image files via a custom API.

The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious user to upload a file that is not an image.

Certain web-server configurations may serve the uploaded file with its actual MIME type rather than an image type. This may lead to cross-site scripting (XSS) or other unexpected behavior.

Solution: 

Install the latest version:

  • If you use the 1.4.1 version of Canvas, upgrade to 1.4.2
  • If you use the 1.5.1 version of Canvas, upgrade to 1.5.2
  • If you use the 1.6.0 version of Canvas, upgrade to 1.6.1
  • If you use the 1.7.0 version of Canvas, upgrade to 1.7.1
Reported By: 
  • Christian López Espínola (penyaskito)
Fixed By: 
  • AKHIL BABU (akhil babu)
  • Christian López Espínola (penyaskito)
Coordinated By: 
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065

1 Juli, 2026 - 19:20
Project: Drupal CanvasDate: 2026-July-01Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Improper validationAffected versions: <1.4.2 || >=1.5.0 <1.5.2 || >=1.6.0 <1.6.1 || >=1.7.0 <1.7.1CVE IDs: CVE-2026-58587Description: 

The Canvas AI submodule allows you to upload image files via a custom API to use within the AI web chat.

These file uploads are insufficiently validated before being written to Drupal's temporary directory. In some cases, this may lead to cross-site scripting (XSS).

Solution: 

Install the latest version:

  • If you use the 1.4.1 version of Canvas, upgrade to 1.4.2
  • If you use the 1.5.1 version of Canvas, upgrade to 1.5.2
  • If you use the 1.6.0 version of Canvas, upgrade to 1.6.1
  • If you use the 1.7.0 version of Canvas, upgrade to 1.7.1
Reported By: 
  • AKHIL BABU (akhil babu)
Fixed By: 
  • Alex Bronstein (effulgentsia) of the Drupal Security Team
  • Christian López Espínola (penyaskito)
Coordinated By: 
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064

26 Juni, 2026 - 17:27
Project: Tealium iQ Tag ManagementDate: 2026-June-26Security risk: Critical 19 ∕ 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: PHP object injectionAffected versions: <2.4.0CVE IDs: CVE-2026-13244Description: 

The Tealium iQ Tag Management module provides Drupal integration with Tealium iQ.

tealiumiq stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an Object Injection vulnerability when the data are unserialized.

This vulnerability is mitigated by the fact that an attacker must have permission to edit a content entity with an attached tealiumiq field. In addition, the core jsonapi module must be enabled with the option "Accept all JSON:API create, read, update, and delete operations", which is not the default, or the attacker needs some other way to edit field values directly.

Note: This project was marked as Unsupported by the Drupal Security Team on 2026-06-24 but a fix was released and the project restored on 2026-06-26.

Solution: 

Install the latest version:

  • If you use the Tealium iQ Tag Management module, upgrade to Tealium iQ Tag Management 8.x.2.4
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Benji Fisher (benjifisher) of the Drupal Security Team
  • Daniel Schiavone (schiavone)
Coordinated By: 
  • Benji Fisher (benjifisher) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063

24 Juni, 2026 - 20:48
Project: Salesforce SuiteDate: 2026-June-24Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site request forgeryAffected versions: <5.1.3CVE IDs: CVE-2026-13243Description: 

The Salesforce Suite of modules integrates Drupal with Salesforce.

The Salesforce module does not properly validate the OAuth handshake during interactive authentication, allowing an attacker to hijack the authorization token and bind the site to an attacker's Salesforce account.

This vulnerability is mitigated by the fact that salesforce_oauth submodule must be enabled, and a salesforce_oauth authorization profile active and in use. The submodule salesforce_oauth is deprecated, and salesforce_jwt has been the recommended authentication plugin for several years. Sites with salesforce_oauth uninstalled, or sites relying exclusively on salesforce_jwt (JWT or JWT Gov Cloud) for authentication are not impacted.

Submodule salesforce_oauth has been removed in branch 6.0.x, so >= 6.0.x versions are not affected by this vulnerability.

Solution: 

Recommended solution:

  • Update to Salesforce Suite version 5.1.3
  • Uninstall salesforce_oauth module

Alternative solution, if you must continue to use salesforce_oauth module:

  • Update to Salesforce Suite version 5.1.3
  • Revoke existing oauth provider tokens
  • Re-authenticate all existing oauth providers
Reported By: 
  • Muhammedali Aliyev (swordmein)
Fixed By: 
  • Aaron Bauman (aaronbauman)
Coordinated By: 
  • Neil Drumm (drumm) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062

24 Juni, 2026 - 20:46
Project: Geolocation FieldDate: 2026-June-24Security risk: Critical 19 ∕ 25 AC:Basic/A:None/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: SQL InjectionAffected versions: <3.15.0CVE IDs: CVE-2026-13242Description: 

Geolocation modules adds a field to store coordinates and provides supporting plumbing for views and other modules.

One of the provided views filters does not sufficiently sanitize values if exposed to user input resulting in a SQL injection vulnerability.

This vulnerability is mitigated by the fact that a view must exist, that uses the aforementioned filter and it is set to accept user input.

Solution: 

Install the latest version:

  • If you use the Geolocation Field module for Drupal, upgrade to Geolocation Field 8.x-3.15
Reported By: 
  • Michael Maturi (michaelmaturi)
Fixed By: 
  • Michael Maturi (michaelmaturi)
  • Christian Adamski (christianadamski)
Coordinated By: 
  • cilefen (cilefen) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061

24 Juni, 2026 - 20:43
Project: ParagraphsDate: 2026-June-24Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.21.0CVE IDs: CVE-2026-13241Description: 

The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to direct child paragraphs of library items through API endpoints.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use and general write access to paragraphs through another module must be allowed.

Solution: 

Install the latest version:

  • If you use the Paragraphs module for Drupal 8.x, upgrade to Paragraphs 8.x-1.21
Reported By: 
  • Mustafa Ahmed (mustafa007)
Fixed By: 
  • Sascha Grossenbacher (berdir)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060

24 Juni, 2026 - 20:42
Project: ParagraphsDate: 2026-June-24Security risk: Less critical 9 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.21.0CVE IDs: CVE-2026-13240Description: 

The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to unpublished library items in lists.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use, and that an attacker must have access to a list of library items, such as a field with autocomplete suggestions or a view.

Solution: 

Install the latest version:

  • If you use the Paragraphs module for Drupal 8.x, upgrade to Paragraphs 8.x-1.21
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Sascha Grossenbacher (berdir)
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security
  • « erste Seite
  • ‹ vorherige Seite
  • 1
  • 2
  • 3
  • 4
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
  • Ich brauche dringen Hilfe zu Updates oder ggf. wwie geht Composer?
  • Dynamische Ansicht von Seiteninhalt (als Tabelle?)
  • Vergabe von Berechtigungen für bestimmte Rollen; mir fehlt der Haken bzw. das „Veröffentlicht“
  • Medien und andere Daten mit Feeds von Drupal 7 auf Drupal 10 migrieren
  • Rolle erstellen nicht zu finden
  • für drupal11 ein Slider Modul
Weiter

Neue Kommentare

  • Gefunden
    vor 7 Wochen 17 Stunden
  • Vielen Dank für die ausführlichen Hinweise...
    vor 7 Wochen 4 Tagen
  • Mögliche Ursachen und nächste Schritte
    vor 7 Wochen 4 Tagen
  • Was für einen Server benutzt
    vor 10 Wochen 19 Stunden
  • Wenn die Subdomain auf
    vor 10 Wochen 2 Tagen
  • ordnerstruktur
    vor 10 Wochen 3 Tagen
  • Die Subdomain muß auf den
    vor 10 Wochen 5 Tagen
  • Verwende doch das Tag dafür,
    vor 14 Wochen 9 Stunden
  • Guckst du hier: step by step
    vor 13 Wochen 6 Tagen
  • Guckst du hier: step by step
    vor 13 Wochen 6 Tagen

Statistik

Beiträge im Forum: 250294
Registrierte User: 20542

Neue User:

  • Kupit_hiPi
  • Thomasbxh
  • Kupit_qsPi

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 25 Gäste online.

Drupal Security

  • Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099
  • External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
  • Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097
  • Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
  • Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association