Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Herkunft ›

Drupal Contrib Security

Inhalt abgleichen
URL: https://www.drupal.org/security/contrib
Aktualisiert: vor 48 Minuten 56 Sekunden

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171

23 September, 2026 - 18:26
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Exploit/TD:UncommonVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96364Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The Webform Share submodule can expose a webform for embedding on another site.

Under certain circumstances, submissions for an Ajax-enabled Webform using Webform Share can bypass anti-spam protections.

This vulnerability is mitigated by the fact that Webform Share must be enabled, sharing must be enabled for the affected webform, and the affected webform must rely on compatible Form-API-based anti-spam protections such as Honeypot or Antibot.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • karing
Fixed By: 
  • Alan Dixon (adixon)
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Mori Sugimoto (dokumori) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Less critical - Denial of service - SA-CONTRIB-2026-170

23 September, 2026 - 18:26
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Less critical 8 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:UncommonVulnerability: Denial of serviceAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96365Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Forms may be displayed in blocks.

Webform does not sufficiently validate an optional token query value before using it. Under specific configurations where a Webform is rendered for anonymous visitors, a malicious request can cause the request to consume significant resources leading to a Denial of Service.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Majdi Alomari (majdi)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169

23 September, 2026 - 18:25
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96366Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Site builders may also configure handlers for processing submissions, including email handlers that may include uploaded files as attachments.

In affected configurations, Webform did not sufficiently validate a managed file upload element when processing a new submission. A user with access to submit a vulnerable webform could potentially access other managed files they were not authorized to view.

This vulnerability is mitigated by the fact that a site must have a Webform with a managed file upload element and a configuration that exposes submitted files, such as allowing users to view their own webform submissions or sending uploads as email attachments.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Sandro Kneubühl (blackpharao)
  • omidsec
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Heine Deelstra (heine) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168

23 September, 2026 - 18:20
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96373Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently validate requested filenames when serving generated submission exports. Under certain configurations, a user with permission to view submission results for one webform may be able to access or remove files from the configured export temporary directory that were not generated for that webform.

This vulnerability is mitigated by the fact that an attacker must have access to view submission results for a webform and must know or be able to determine a target filename.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167

23 September, 2026 - 18:18
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96372Description: 

The Webform module enables site builders to create forms and collect submissions.

The module does not sufficiently restrict access to configure Remote HTTP Operations handlers. This vulnerability could allow a user with permission to edit a webform to configure a remote HTTP operation.

The update adds the Administer webform remote post URLs permission. Review this permission and ensure it is granted only to trusted roles.

The vulnerability is mitigated by the fact that an attacker must have a role with permission to edit a webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.11.

Review the new permission Administer webform remote post URLs and ensure it is only granted to trusted roles.

Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Wesley Giles (seraphdev)
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166

23 September, 2026 - 18:17
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96371Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently restrict access to raw webform source editing when the Webform UI module is not enabled. This could allow a user with webform creation or editing permissions to enter source configuration that is rendered unsafely.

This vulnerability is mitigated by the fact that an attacker must have permission to create or edit webforms.

Solution: 

Install the latest version.

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Liam Morland (liam morland)
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Less critical - Access bypass - SA-CONTRIB-2026-165

23 September, 2026 - 18:17
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Less critical 8 ∕ 25 AC:Complex/A:User/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96369Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

When Webform is used with JSON:API enabled, submissions may be cached without varying correctly by the authenticated user. If a webform is configured so that authenticated users can view their own submissions, a request to the JSON:API webform submission collection can return a cached response generated for a different user.

This can allow an authenticated user to view another user's webform submission data through the JSON:API collection endpoint.

This vulnerability is mitigated by the fact that JSON:API must be enabled, the affected webform must expose submissions through JSON:API, and the attacker must have an account with permission to view their own submissions for the affected webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Giuseppe (giuseppe87)
Fixed By: 
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jacob Rockowitz (jrockowitz)
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164

23 September, 2026 - 18:16
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypass, Server-side request forgeryAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96370Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module includes a Webform Submission Export/Import submodule that allows importing submission data from uploaded CSV files or remote URLs.

The submodule did not sufficiently validate access to export/import functionality. A user who could edit webform submissions and access webform results could also access the import interface, including the remote URL import path, leading to a server-side request forgery vulnerability.

Sites that do not enable the Webform Submission Export/Import submodule are not affected.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.

For sites that need remote imports, explicitly configure the trusted hosts in settings.php:

$settings['webform_submission_export_import_csv_hosts'] = ['staging.example.com']; $settings['webform_submission_export_import_file_hosts'] = ['files.staging.example.com', '*.google.com']; Reported By: 
  • abdo.boutanos@richemont.com
  • chulhan park (cjfgks1230)
  • Abdulhakeem Onipede (kism37)
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Marcus Johansson (marcus_johansson)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163

23 September, 2026 - 18:16
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96368Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may add tooltips and help text to these forms.

Some Webform tooltips and help text were not sufficiently sanitized, resulting in possible cross-site scripting (XSS).

This vulnerability is mitigated by the fact that an attacker must have permission to create or edit affected Webform configuration or content.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162

23 September, 2026 - 18:15
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96367Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently restrict access to the custom attributes YAML editor. Users with permission to create or edit webforms (but without permission to edit webform source) may be able to add custom attributes, leading to cross-site scripting.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit webforms.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Mitch Portier (arkener)
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161

23 September, 2026 - 18:14
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96363Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.

This vulnerability is mitigated by the fact that an attacker must have a role with create webform and edit own webform permissions, and the Webform Entity Print module must be enabled.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Cathy Theys (yesct) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160

23 September, 2026 - 18:14
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96362Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Remote Post Handlers send webform data to other servers via APIs.

The module does not sufficiently filter response values from the Remote Post handler before those values are rendered through handler response tokens. If a site uses Remote Post handler response tokens in rendered output, values returned by a configured remote endpoint could be rendered as HTML, resulting in a cross-site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to control or influence the response from a configured remote endpoint, and the site must use Remote Post handler response tokens in rendered output.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Brian Willows (hsjbrianwillows)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159

23 September, 2026 - 18:13
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96359Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module did not sufficiently sanitize attributes used by its color element. Under certain conditions, specially crafted attributes could result in cross-site scripting (XSS) when the element is rendered.

This vulnerability is mitigated by the fact that an attacker must be able to add a specially crafted link with a specific class to the same page as the affected webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158

23 September, 2026 - 18:13
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96358Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module includes a rating element, which did not sufficiently validate its data. Under specific circumstances, this could allow cross-site scripting on a page with a rating element.

This vulnerability is mitigated by the fact that an attacker must be able to place crafted HTML markup on the same page as a Webform rating element.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155

23 September, 2026 - 18:11
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96361Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently sanitize text counter configuration before passing options to the bundled jQuery Text Counter library. Under certain configurations, this can allow markup from counter-related settings to be inserted into the page leading to a cross-site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to create or edit affected Webform elements, or place specially crafted counter markup on a page where the Webform counter JavaScript is active.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154

23 September, 2026 - 18:11
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96360Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module provides JavaScript behaviours for announcing dynamic form updates to assistive technologies.

In some configurations, due to improper sanitisation, specially crafted announcement text could create a cross-site scripting risk for users interacting with the affected Webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153

9 September, 2026 - 19:24
Project: Ultimate Table FieldProject machine name: ultimate_table_fieldDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.1.1 || >=2.0.0 <2.0.1CVE IDs: CVE-2026-87955Description: 

The Ultimate Table Field module enables you to store table data in a field and edit each table cell through a dialog, using cell field plugins such as text, link, and file.

The module doesn't sufficiently protect the route that opens the cell editor dialog. The route is accessible to anonymous users, who can open the dialog for any cell type. The dialog allows uploading files to the server location.

This vulnerability is partially mitigated by the fact that only files with the pdf, doc and docx extensions are accepted.

Solution: 

Install the latest version and adjust permissions:

  • If you use the 2.x branch of the Ultimate Table Field module , upgrade to Ultimate Table Field 2.0.1.
  • If you use the 1.x branch of the Ultimate Table Field module , upgrade to Ultimate Table Field 1.1.1.

After updating, grant the new permission Use the Ultimate Table Field cell editor to every role that edits content containing an Ultimate Table field. Without it, editors can no longer open the cell editor dialog.

Releases of the 1.0.x branch are not supported and do not receive security coverage. Upgrade to 1.1.1 or 2.0.1.

Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Brahim Khouy (b.khouy)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152

9 September, 2026 - 19:24
Project: Taxonomy Term GlossaryProject machine name: term_glossaryDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <4.6.0CVE IDs: CVE-2026-87954Description: 

This module adds automatic highlighting of taxonomy terms in content.

The module doesn't sufficiently check access on taxonomy terms. As a result, anonymous users can view any of the site's taxonomy terms at the module's JSON endpoint, including taxonomy terms that are unpublished or otherwise restricted.

Solution: 

Install the latest version:

  • If you use the Taxonomy Term Glossary module, upgrade to term_glossary 4.6.0.

The 4.4.x and 4.5.x branches are no longer supported.

Reported By: 
  • Hemant Gupta (guptahemant)
  • Marcus Johansson (marcus_johansson)
  • Serhii Checheniev (serhii-che)
Fixed By: 
  • Frank Mably (mably)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Moderately critical - Server Side Request Forgery - SA-CONTRIB-2026-151

9 September, 2026 - 19:23
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Server Side Request ForgeryAffected versions: <3.2.0CVE IDs: CVE-2026-87953Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not sufficiently validate URLs obtained from identity provider metadata. An attacker with the ability to configure identity provider metadata could cause the application to make requests to unintended destinations, potentially allowing access to internal network resources.

This vulnerability is mitigated by the fact that an attacker must have permission to configure identity provider metadata.

Solution: 

Install the latest version:

  • Upgrade to miniorange_saml 3.2.0.
Reported By: 
  • Brian Willows (hsjbrianwillows)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Moderately critical - Insufficient replay protection - SA-CONTRIB-2026-150

9 September, 2026 - 19:23
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:User/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Insufficient replay protectionAffected versions: <3.2.0CVE IDs: CVE-2026-87952Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not sufficiently prevent reuse of previously accepted SAML assertions. Under certain circumstances, a valid assertion may be replayed within its validity period, potentially allowing repeated authentication attempts using the same assertion.

This vulnerability is mitigated by the fact that an attacker must first obtain a valid SAML assertion and can only reuse it during the assertion's validity period.

Solution: 

Install the latest version:

  • Upgrade to miniorange_saml 3.2.0.
Reported By: 
  • Brian Willows (hsjbrianwillows)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security
  • « erste Seite
  • ‹ vorherige Seite
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Canvas Palette: Eine fertige Komponentenbibliothek für Drupal Canvas
  • Hilfe zu Updates oder Composer
  • Vergleich Drupal und Contao
  • [geloest] Blocks in Bootstrap nebeneinander darstellen und nicht untereinander
  • DrupalCamp Frankfurt 27-28 November 2026
  • Bitte mein Bentzerkonto löschen
  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
Weiter

Neue Kommentare

  • Danke ich werde mir die
    vor 2 Wochen 3 Tagen
  • Vielen Dank für Ihren
    vor 2 Wochen 6 Tagen
  • Composer ist sehr ratsam
    vor 3 Wochen 23 Stunden
  • Vielen Dank für den
    vor 3 Wochen 3 Tagen
  • Die alten CMS Vergleiche von contentmanager.de
    vor 3 Wochen 3 Tagen
  • Gut gemacht
    vor 3 Wochen 3 Tagen
  • Layout Builder etc. z.B. für Landing Pages
    vor 3 Wochen 3 Tagen
  • Links
    vor 3 Wochen 6 Tagen
  • Moin,wow, sehr gutes
    vor 4 Wochen 13 Stunden
  • Dass ist eine spannende
    vor 4 Wochen 21 Stunden

Statistik

Beiträge im Forum: 250316
Registrierte User: 20564

Neue User:

  • Robertspaft
  • drupalthemes
  • rofilm

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 39 Gäste online.

Drupal Security

  • Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
  • Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association