Drupal Contrib Security
LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
This module configures default editorial workflows for LocalGov Drupal content types. It provides a Drupal content moderation workflow, a content approvals dashboard, content scheduling and content preview.
The module doesn't sufficiently restrict access to a view of Service Contacts at which exposes the names and content items assigned to each Service Contact.
Solution:Install the latest version:
- If you use the LocalGov Workflows module for Drupal, upgrade to LocalGov Workflows 1.6.0
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038
The Basket module enables e-commerce and checkout functionality for Drupal sites.
The module does not sufficiently sanitize user-supplied data before passing it to PHP's unserialize().
An attacker can supply a crafted payload and trigger PHP Object Injection. If a viable gadget chain exists in the site codebase or installed dependencies, this can result in arbitrary PHP code execution.
Solution:Install the latest version:
- If you use the Basket module, upgrade to Basket 2.1.17.
- Drew Webber (mcdruid) of the Drupal Security Team
- Helena Zajika (helena zajika)
- Drew Webber (mcdruid) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037
This module enables you to export entity date fields as iCal feeds.
The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds.
This vulnerability is not mitigated by any permission, the routes are accessible to all anonymous users with no configuration required.
Solution:Install the latest version:
- If you use the Date iCal module for Drupal 10/11, upgrade to Date iCal 4.0.15
- Drew Webber (mcdruid) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
Colorbox Inline - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-036
This module enables you to open content already on the page within a colorbox.
The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.
Solution:Install the latest version:
- If you use the Colorbox Inline module for Drupal 8.x, upgrade to Colorbox Inline 2.1.1
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
The GTranslate module provides a language switcher widget for Drupal sites.
The module’s widget JavaScript did not sufficiently validate that document.currentScript referred to the executing script element. A user who can add HTML to a page could cause the generated language-switcher links to point to an unintended domain.
This vulnerability is mitigated by the fact that an attacker must be able to add HTML with attributes that are not allowed by Drupal’s default CKEditor configuration. It is also limited to sites using the paid versions of GTranslate widget JavaScript and configurations where the generated language links use script-provided values.
Solution:Install the latest version.
If you use the GTranslate module 3.0.x, upgrade to GTranslate 3.0.5.
Reported By:- Pierre Rudloff (prudloff) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034
Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page
The module doesn't sufficiently handle the case where a user is cancelled and their content is reassigned to the anonymous user.
This vulnerability is mitigated by the fact that only private contents where anonymous should not have view access are affected, and only if a node was reassigned to the anonymous user.
Install the latest version:
- If you use the Node View Permissions module version 2.0.0. or prior, upgrade to 2.0.1.
- If you use the Node View Permissions module version 8.x-1.6. or prior, upgrade to 8.x-1.7.
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team

Neue Kommentare
vor 7 Wochen 17 Stunden
vor 7 Wochen 4 Tagen
vor 7 Wochen 4 Tagen
vor 10 Wochen 19 Stunden
vor 10 Wochen 2 Tagen
vor 10 Wochen 3 Tagen
vor 10 Wochen 5 Tagen
vor 14 Wochen 9 Stunden
vor 13 Wochen 6 Tagen
vor 13 Wochen 6 Tagen