Drupal Contrib Security
Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129
A module to import media files into media library.
The import folder is a plain textfield with no validation. Point it at any directory the web user can read, and the importer copies every file whose extension matches a selected media type into the public files directory and publishes it as a Media entity. Files that were deliberately kept outside the webroot, such as a private file store, become downloadable by anonymous visitors at a predictable URL.
Solution:Install the latest version:
- If you use the Media Library Importer module for Drupal upgrade to Media Library Importer 2.1.6
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128
This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports > Mail log.
The module doesn't sufficiently redact the content of the emails it logs. Account related emails are stored with their one-time login links intact, so any user who can view the log can obtain a one-time login link for any account, including user 1, and use it to log in as that account.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission View Drupal Symfony Mailer log entries, which in earlier releases was not marked as a restricted permission.
Solution:Install the latest version:
- If you use the Mailer Plus Log module (previously known as Symfony Mailer Log), upgrade to Mailer Plus Log 1.2.7
- After updating, run database updates so that the email bodies already stored in the log are redacted.
- Review who should have the View Drupal Symfony Mailer log entries permission, and whether your site sends out custom sensitive emails that would need to opt in to the redaction logic.
- Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
- Sven Decabooter (svendecabooter)
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Mohit Aghera (mohit_aghera)
Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127
This module enables you to restrict access to JSON:API routes based on specific user roles.
The module doesn't sufficiently enforce access controls under scenarios where a request mimics an XMLHttpRequest.
Solution:Install the latest version:
- If you use the Jsonapi Role Access module, upgrade to Jsonapi Role Access 2.0.2
- Drew Webber (mcdruid) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126
This islandora_advanced_search sub module enables AJAX updates for advanced search, facet, and search result blocks.
The module doesn't sufficiently check block access when arbitrary block ID's are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.
This vulnerability is mitigated by the fact that an attacker must know or guess a restricted block’s machine ID, and the block must contain sensitive content protected by block access or visibility restrictions. Additionally, the submodule is not known to be used by any modern Islandora configurations.
Solution:Install the latest version:
- If you use the Islandora module, upgrade to the latest version Islandora 2.19.0. Be sure to read the release node for advice on updating
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Email Verification / SMS Verification / OTP Verification - Critical - Cross Site Scripting - SA-CONTRIB-2026-125
This module enables you to add an extra layer of verification for user registration.
The module doesn't sufficiently filter user-supplied input before output, resulting in an unauthenticated reflected Cross-site Scripting (XSS) vulnerability.
Solution:Install the latest version:
If you are using the OTP Verification module for Drupal, upgrade to the latest version 8.x-2.4
Reported By:- Drew Webber (mcdruid) of the Drupal Security Team
- Mohammed Hisam (hisam45)
- Drew Webber (mcdruid) of the Drupal Security Team
- Sudhanshu Dhage (sudhanshu0542)
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Email Verification / SMS Verification / OTP Verification - Critical - Access Bypass - SA-CONTRIB-2026-124
This module enables you to add extra layer of verification for user registration.
The module doesn't sufficiently validate user-supplied input resulting in an account takeover vulnerability.
Solution:Install the latest version:
If you are using the OTP Verification module for Drupal, upgrade to latest version 8.x-2.4
Reported By:- Drew Webber (mcdruid) of the Drupal Security Team
- Mohammed Hisam (hisam45)
- Drew Webber (mcdruid) of the Drupal Security Team
- Sudhanshu Dhage (sudhanshu0542)
- Swan Kalata (akalata) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Component blocks - Moderately critical - Cross site scripting - SA-CONTRIB-2026-123
This module enables you use UI Patterns with blocks, for use in Layout Builder.
The module doesn't sufficiently validate user input before passing to token replacement.
This vulnerability is mitigated by the fact that an attacker must have a role with the ability to edit layout builder layouts.
Solution:Install the latest version:
- If you use the component_blocks module, upgrade to Component Blocks 1.2.7
- Lee Rowlands (larowlan) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
Calculate Working Days - Critical - Access bypass - SA-CONTRIB-2026-122
Calculate Working Days allows you to calculate working days
between 2 dates.
This module doesn't sufficiently restrict access to its settings form.
Solution:Install the latest version:
- If you use the Calculate Working Days module, upgrade to calculate_working_days 2.0.3
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
AI translate - Moderately critical - Access Bypass - SA-CONTRIB-2026-121
This module enables you to automatically translate entities.
The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities
Solution:Install the latest version:
- If you use AI Translate 1.3.x, upgrade to AI Translate 1.3.2
- If you use AI Translate 1.4.x, upgrade to AI Translate 1.4.1
- Artem Dmitriiev (a.dmitriiev)
- Marcus Johansson (marcus_johansson)
- Sven Decabooter (svendecabooter)
- Valery Lourie (valthebald)
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
AI (Artificial Intelligence) - Moderately critical - Access Bypass - SA-CONTRIB-2026-120
This submodule AI Translate enables you to automatically translate entities.
The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities
Solution:Install the latest version:
- If you use the AI module 1.4.7 or below upgrade to AI module 1.4.8
- If you use the AI module 1.3.12 or below upgrade to AI module 1.3.13
- Artem Dmitriiev (a.dmitriiev)
- Marcus Johansson (marcus_johansson)
- Sven Decabooter (svendecabooter)
- Valery Lourie (valthebald)
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119
This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website.
The module doesn't sufficiently sanitize for cross site scripting (XSS) when using the structured results using legacy agent setups.
This vulnerability is mitigated by the fact that an attacker must be able to invoke a prompt injection set via editorial content and the site must have been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon configuration. Any configuration setup or updated after these minor versions are not affected.
Solution:Install the latest version:
- If you use the AI module 1.4.7 or below upgrade to AI module 1.4.8
- If you use the AI module 1.3.12 or below upgrade to AI module 1.3.13
- Drew Webber (mcdruid) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
Advanced Search - Moderately critical - Access bypass - SA-CONTRIB-2026-118
This module enables AJAX updates for advanced search, facet, and search result blocks.
The module doesn’t sufficiently check block access when arbitrary block IDs are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.
This vulnerability is mitigated by the fact that an attacker must know or guess a restricted block’s machine ID, and the block must contain sensitive content protected by block access or visibility restrictions.
Solution:Install the latest version:
- If you use the Advanced Search module, upgrade to Advanced Search 2.4.5
- Swan Kalata (akalata) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117
Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.
Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.
Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.
Solution:- Only the 3.0.x branch is supported by the maintainers. Upgrade to a release on that branch.
- Drew Webber (mcdruid) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- cilefen of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116
This module enables you to create one or more multisites with highly granular page permissions.
The module doesn't sufficiently sanitize HTML code contained in the page name when displayed in the built-in tree browser. This results in a cross-site scripting vulnerability that may allow attackers to execute arbitrary JavaScript in the context of the user’s session.
This vulnerability is mitigated by the fact that an attacker must have the ability to create pages whose page title supports HTML.
Solution:Install the latest version:
- If you use the Monster Menus module, upgrade to monster_menus 9.5.3.
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
This module enables users to authenticate using LDAP or Active Directory credentials.
The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.
Solution:Install the latest version:
- If you use the LDAP / Active Directory Integration module, upgrade to LDAP / Active Directory Integration 2.2.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114
The Entity PDF module can create a PDF from any entity based on any View mode.
This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.
Solution:Install the latest version:
- If you use the Entity PDF module for Drupal upgrade to Entity PDF 2.1.5.
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.
The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.
This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.
Solution:Install the latest version:
- If you use the Entity API module, upgrade to Entity API 8.x-1.8.
- Sascha Grossenbacher (berdir)
- Klaus Purer (klausi)
- Kristiaan Van den Eynde (kristiaanvandeneynde)
- Matt Glaman (mglaman)
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata.
The 2.x version of the module does not sufficiently restrict access to API credentials in JavaScript settings. When AI agent features are enabled, the token is exposed to all page visitors (including anonymous users) via drupalSettings.
This vulnerability is mitigated by the fact that a site must have DXPR Builder AI features enabled and configured with an API token.
Solution:Install the latest version:
- If you use the 2.x branch of the DXPR Builder module, upgrade to DXPR Builder 2.8.1 or later.
- The 3.x branch is not affected as it proxies AI requests through the contributed AI module.
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
This module enables you to disable access to the /user/login form unless a secret key is provided.
The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may remain accessible until caches are cleared. An attacker may continue to access the login page despite the restriction having been enabled.
Solution:Install the latest version:
- If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110
This module enables you to disable access to the /user/login form unless a secret key is provided.
The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.
Solution:Install the latest version:
- If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team

Neue Kommentare
vor 2 Wochen 3 Tagen
vor 2 Wochen 6 Tagen
vor 3 Wochen 23 Stunden
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 6 Tagen
vor 4 Wochen 13 Stunden
vor 4 Wochen 21 Stunden