Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Herkunft ›

Drupal Contrib Security

Inhalt abgleichen
URL: https://www.drupal.org/security/contrib
Aktualisiert: vor 48 Minuten 16 Sekunden

SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149

9 September, 2026 - 19:22
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Information disclosureAffected versions: <3.2.0CVE IDs: CVE-2026-87951Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module stores sensitive authentication information in a manner that could allow disclosure to users with access to configuration or related system data.

This vulnerability is mitigated by the fact that an attacker must first obtain access to configuration or underlying storage mechanisms.

Solution: 

Install the latest version:

  • Upgrade to SAML SSO - Service Provider 3.2.0.
Reported By: 
  • Sudhanshu Dhage (sudhanshu0542)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148

9 September, 2026 - 19:22
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Embedded credentialsAffected versions: <3.2.0CVE IDs: CVE-2026-87950Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module contains embedded credentials used by the functionality provided by the module.

Under certain circumstances, these credentials could allow information about associated services to be disclosed.

Solution: 

Install the latest version:

  • Upgrade to miniorange_saml 3.2.0.
Reported By: 
  • Sudhanshu Dhage (sudhanshu0542)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-147

9 September, 2026 - 19:22
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: <3.2.0CVE IDs: CVE-2026-87949Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not sufficiently sanitize certain values derived from SAML assertions before displaying them to users. A malicious identity provider or an attacker able to supply crafted SAML attributes, leading to a cross-site scripting (XSS) vulnerability.

Solution: 

Install the latest version:

  • Upgrade to miniorange_saml 3.2.0.
Reported By: 
  • Brian Willows (hsjbrianwillows)
Fixed By: 
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146

9 September, 2026 - 19:21
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: <3.2.0CVE IDs: CVE-2026-87948Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not sufficiently sanitize user-supplied data before displaying it in generated HTML leading to a cross-site scripting vulnerability (XSS).

Solution: 

Install the latest version:

  • Upgrade to SAML SSO - Service Provider 3.2.0.
Reported By: 
  • Sudhanshu Dhage (sudhanshu0542)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Moderately critical - Authentication bypass - SA-CONTRIB-2026-145

9 September, 2026 - 19:21
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Authentication bypassAffected versions: <3.2.0CVE IDs: CVE-2026-87947Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not properly restrict which signature algorithm may be used to validate a SAML assertion, allowing the algorithm to be influenced by the incoming response rather than being tied to the type of key configured for the Identity Provider (IdP).

The vulnerability is mitigated by the fact that an attacker must be able to submit a crafted SAML response to the affected site.

Solution: 

Install the latest version:

  • Upgrade to SAML SSO - Service Provider 3.2.0.
Reported By: 
  • Timo De Clercq (timodc)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Heine Deelstra (heine) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144

9 September, 2026 - 19:21
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Weak cryptographic practicesAffected versions: <3.2.0CVE IDs: CVE-2026-87946Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module uses cryptographic constructions that do not align with current security best practices.

The module performs certain signature comparisons using non constant-time comparison logic and generates SAML request identifiers using predictable values derived from non-cryptographic random number generation.

While no practical authentication bypass has been demonstrated as a result of these weaknesses alone, they may reduce the overall security margin of SAML authentication workflows.

Solution: 

Install the latest version:

  • Upgrade to SAML SSO - Service Provider 3.2.0.
Reported By: 
  • Sudhanshu Dhage (sudhanshu0542)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Critical - Open redirect - SA-CONTRIB-2026-143

9 September, 2026 - 19:20
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Open redirectAffected versions: <3.2.0CVE IDs: CVE-2026-87945Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The miniorange_saml module does not sufficiently validate certain user-supplied URLs before performing redirects.

An attacker could cause users to be redirected to an external website after authentication. This could be used in phishing attacks or to increase the credibility of malicious links.

Solution: 

Install the latest version:

  • Upgrade to miniorange_saml 3.2.0.
Reported By: 
  • Sudhanshu Dhage (sudhanshu0542)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142

9 September, 2026 - 19:20
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Improper certificate validationAffected versions: <3.2.0CVE IDs: CVE-2026-87944Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not properly validate TLS certificates when making outbound HTTPS requests.

An attacker in a position to intercept network traffic could impersonate a trusted remote service and influence communications performed by the module.

This vulnerability is mitigated by the fact that an attacker must be able to
intercept or redirect network traffic originating from the site.

Solution: 

Install the latest version:

  • Upgrade to miniorange_saml 3.2.0
Reported By: 
  • Jonni Kalpio (thatguy)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SAML SSO - Service Provider - Critical - Improper access control - SA-CONTRIB-2026-141

9 September, 2026 - 19:19
Project: SAML SSO - Service Provider Project machine name: miniorange_samlDate: 2026-September-09Security risk: Critical 18 ∕ 25 AC:None/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Improper access controlAffected versions: <3.2.0CVE IDs: CVE-2026-87943Description: 

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The miniorange_saml module does not correctly restrict access to certain functionality intended for administrative use. This could allow unauthorized users to access functionality or modify configuration values that should only be available to privileged users.

Solution: 

Install the latest version:

  • Upgrade to SAML SSO - Service Provider 3.2.0.
Reported By: 
  • Brian Willows (hsjbrianwillows)
Fixed By: 
  • Roushan Kumar Singh (roushan59227)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

SafeDelete - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-140

9 September, 2026 - 19:19
Project: SafeDeleteProject machine name: safedeleteDate: 2026-September-09Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <1.0.88CVE IDs: CVE-2026-87942Description: 

This module enables you to manage content deletion and provides reports for identifying orphaned content.

The module doesn't sufficiently sanitize node titles when displaying the orphaned nodes report. This leads to a persistent cross-site scripting vulnerability (XSS).

This vulnerability is mitigated by the fact that an attacker must have permission to create content of a content type configured for the orphaned nodes report.

Solution: 

Install the latest version:

  • If you use the Safe Delete module, upgrade to Safe Delete 1.0.88.
Reported By: 
  • Lee Rowlands (larowlan) of the Drupal Security Team
Fixed By: 
  • Joseph Olstad (joseph.olstad)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Scott Morrison (scottm316)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Patreon - Critical - Unsupported - SA-CONTRIB-2026-139

9 September, 2026 - 19:18
Project: PatreonProject machine name: patreonDate: 2026-September-09Security risk: Critical 16 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:AllVulnerability: UnsupportedCVE IDs: CVE-2026-87941Description: 

The Drupal Security Team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that is unsupported for security reasons.

Solution: 

If you use this project, you should uninstall it.

To take over maintainership, read Becoming the maintainer of a project that is unsupported for security reasons.

Reported By: 
  • Marcus Johansson (marcus_johansson)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138

9 September, 2026 - 19:17
Project: Key authProject machine name: key_authDate: 2026-September-09Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <2.2.4CVE IDs: CVE-2026-87940Description: 

This module enables you to add key-based authentication on a per-user
basis.

The module doesn't cache per user, potentially allowing an attacker to view another user's authentication keys, if the attacker has the same permissions.

This vulnerability is mitigated by the fact that the site must have the dynamic_page_cache module enabled.

Solution: 

Install the latest version:

  • If you use the Key Auth module, upgrade to Key auth 2.2.4.
Reported By: 
  • Utkarsh Choudhary (sisyphus_ut)
Fixed By: 
  • Utkarsh Choudhary (sisyphus_ut)
  • solideogloria
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137

9 September, 2026 - 19:16
Project: Feed BlockProject machine name: feed_blockDate: 2026-September-09Security risk: Moderately critical 13 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: <2.0.2 || >=3.0.0 <3.0.2CVE IDs: CVE-2026-87939Description: 

The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed.

The module does not sufficiently validate or sanitize the RSS feed it generates, resulting in a stored cross-site scripting (XSS) vulnerability.

Solution: 

Install the latest version:

  • If you use the 3.x branch, upgrade to Feed Block 3.0.2.
  • If you use the 2.x branch, upgrade to Feed Block 2.0.2.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Mark Fullmer (mark_fullmer)
  • mmarler
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136

9 September, 2026 - 19:16
Project: CSP logProject machine name: csp_logDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:Basic/A:Admin/CI:All/II:Some/E:Theoretical/TD:AllVulnerability: SQL InjectionAffected versions: <1.0.2CVE IDs: CVE-2026-87938Description: 

The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers.

The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability.

This vulnerability is mitigated by the fact that an attacker needs access to an account with the Access CSP reports permission to exploit the SQL Injection.

Solution: 

Install the latest version:

  • If you use the CSP Log module, upgrade to CSP Log 1.0.2.
Reported By: 
  • eduardo morales alberti
Fixed By: 
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135

9 September, 2026 - 19:15
Project: Central Authentication System (CAS) ServerProject machine name: cas_serverDate: 2026-September-09Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:AllVulnerability: Open redirectAffected versions: <2.0.4 || >=2.1.0 <2.1.3CVE IDs: CVE-2026-87937Description: 

This module enables you to turn a Drupal install into the Central Authentication System (CAS) Server. It makes your database the primary location for other systems to use for authentication in a SSO environment.

The module doesn't sufficiently check the service URL used to redirect the user during logout, leading to an open redirect.

This vulnerability is mitigated by the fact that an attacker must convince a user to click a specially crafted link. The vulnerability cannot be exploited without user interaction and does not allow an attacker to directly compromise the CAS server or bypass authentication.

Solution: 

Install the latest version of Central Authentication System (CAS) Server module:

  • If you use the 2.0.x branch, upgrade to CAS Server 2.0.4.
  • If you use the 2.1.x branch, upgrade to CAS Server 2.1.3
Reported By: 
  • Kalle Kipinä (kekkis)
Fixed By: 
  • Ted Cooper (elc)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134

9 September, 2026 - 19:14
Project: amazee.ai Private AI ProviderProject machine name: ai_provider_amazeeioDate: 2026-September-09Security risk: Critical 17 ∕ 25 AC:Complex/A:None/CI:All/II:Some/E:Proof/TD:DefaultVulnerability: SQL injectionAffected versions: <1.3.7 || >=1.4.0 <1.4.3CVE IDs: CVE-2026-87936Description: 

Update 2026-09-11: Increased risk score to reflect publicly documented methods for developing exploits.

This module integrates amazee.ai's AI services into Drupal, including a Postgres/pgvector vector database backend for use with Search API AI Search.

The module doesn't sufficiently sanitize filter values before using them to build SQL queries in its Postgres/pgvector backend, allowing SQL injection.

This vulnerability is mitigated by the fact that a site must be using the module's Postgres/pgvector vector database backend for a Search API AI Search index, and must expose one of that index's non-string fields as a filter (for example, through a View) that is reachable by the attacker.

Solution: 

Install the latest version:

  • If you use the amazee.ai AI Provider module for Drupal 1.4.x, upgrade to ai_provider_amazeeio 1.4.3.
  • If you use the 1.3.x branch, upgrade to ai_provider_amazeeio 1.3.7.
Reported By: 
  • Matan Kotick (matank001)
Fixed By: 
  • Dan Lemon (dan2k3k4)
  • Dimitris Spachos (dspachos)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Webform Submissions Delete - Moderately critical - Access bypass - SA-CONTRIB-2026-133

2 September, 2026 - 18:39
Project: Webform Submissions DeleteProject machine name: webform_submissions_deleteDate: 2026-September-02Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.2.0CVE IDs: CVE-2026-84921Description: 

This module enables you to delete Webform submissions in bulk using a specified date range.

The module doesn't sufficiently restrict access to the delete form.

A separate PHP fatal error issue may prevent exploitation in practice on Drupal 10+.

Solution: 

Install the latest version:

  • If you use the Webform Submissions Delete module, upgrade to Webform Submissions Delete 8.x-1.2
Reported By: 
  • Bernhard Karimi (bernhardk_oww)
Fixed By: 
  • solideogloria
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Dan Smith (galooph) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132

2 September, 2026 - 18:38
Project: Unpublished Node PermissionsProject machine name: unpublished_node_permissionsDate: 2026-September-02Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.8.0CVE IDs: CVE-2026-84920Description: 

This module creates permissions per node content type to control access to unpublished content.

The module has allowed view access for published content, overriding other access mechanisms that might have been in place.

Solution: 

Install the latest version:

  • If you use the Unpublished Node Permissions module, upgrade to Unpublished Node Permissions 8.x-1.8.
Reported By: 
  • Erwin Eggenberger (eeg)
  • Jon Jordan (joncjordan)
Fixed By: 
  • Fabien Gutknecht (fabsgugu)
  • Jon Jordan (joncjordan)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-131

2 September, 2026 - 18:37
Project: PhotoSwipe - Responsive JavaScript Modal Image GalleryProject machine name: photoswipeDate: 2026-September-02Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: <5.0.9CVE IDs: CVE-2026-84919Description: 

This module enables you to add dynamic caption support to PhotoSwipe image galleries.

The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.

Solution: 

Install the latest version:

  • If you use the photoswipe_dynamic_caption module, upgrade to photoswipe 5.0.9
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Joshua Sedler (grevil)
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Monobank payment API - Moderately critical - Access bypass - SA-CONTRIB-2026-130

2 September, 2026 - 18:36
Project: Monobank payment APIProject machine name: monobankDate: 2026-September-02Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.0.3CVE IDs: CVE-2026-84918Description: 

The Monobank payment API module provides integration with Monobank acquiring payments.

The module did not verify the Monobank webhook signature before processing payment status callbacks.

Solution: 

Install the latest version:

  • If you use the Monobank payment API module, upgrade to the monobank 1.0.3.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Helena Zajika (helena zajika)
  • Marcus Johansson (marcus_johansson)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security
  • « erste Seite
  • ‹ vorherige Seite
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Canvas Palette: Eine fertige Komponentenbibliothek für Drupal Canvas
  • Hilfe zu Updates oder Composer
  • Vergleich Drupal und Contao
  • [geloest] Blocks in Bootstrap nebeneinander darstellen und nicht untereinander
  • DrupalCamp Frankfurt 27-28 November 2026
  • Bitte mein Bentzerkonto löschen
  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
Weiter

Neue Kommentare

  • Danke ich werde mir die
    vor 2 Wochen 3 Tagen
  • Vielen Dank für Ihren
    vor 2 Wochen 6 Tagen
  • Composer ist sehr ratsam
    vor 3 Wochen 23 Stunden
  • Vielen Dank für den
    vor 3 Wochen 3 Tagen
  • Die alten CMS Vergleiche von contentmanager.de
    vor 3 Wochen 3 Tagen
  • Gut gemacht
    vor 3 Wochen 3 Tagen
  • Layout Builder etc. z.B. für Landing Pages
    vor 3 Wochen 3 Tagen
  • Links
    vor 3 Wochen 6 Tagen
  • Moin,wow, sehr gutes
    vor 4 Wochen 13 Stunden
  • Dass ist eine spannende
    vor 4 Wochen 21 Stunden

Statistik

Beiträge im Forum: 250316
Registrierte User: 20564

Neue User:

  • Robertspaft
  • drupalthemes
  • rofilm

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 41 Gäste online.

Drupal Security

  • Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
  • Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association