Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Herkunft ›

Drupal Contrib Security

Inhalt abgleichen
URL: https://www.drupal.org/security/contrib
Aktualisiert: vor 32 Minuten 5 Sekunden

LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039

3 Juni, 2026 - 18:10
Project: LocalGov WorkflowsDate: 2026-June-03Security risk: Moderately critical 14 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Information disclosureAffected versions: <1.6.0CVE IDs: CVE-2026-10768Description: 

This module configures default editorial workflows for LocalGov Drupal content types. It provides a Drupal content moderation workflow, a content approvals dashboard, content scheduling and content preview.

The module doesn't sufficiently restrict access to a view of Service Contacts at which exposes the names and content items assigned to each Service Contact.

Solution: 

Install the latest version:

  • If you use the LocalGov Workflows module for Drupal, upgrade to LocalGov Workflows 1.6.0
Reported By: 
  • Maria Young (maria.y)
Fixed By: 
  • Finn Lewis (finn lewis)
  • Rupert Jabelman (rupertj)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038

27 Mai, 2026 - 20:32
Project: Drupal AlternativeCommerce (Basket)Date: 2026-May-27Security risk: Highly critical 22 ∕ 25 AC:None/A:None/CI:All/II:All/E:Theoretical/TD:AllVulnerability: Arbitrary PHP code executionAffected versions: <2.1.17CVE IDs: CVE-2026-9726Description: 

The Basket module enables e-commerce and checkout functionality for Drupal sites.

The module does not sufficiently sanitize user-supplied data before passing it to PHP's unserialize().

An attacker can supply a crafted payload and trigger PHP Object Injection. If a viable gadget chain exists in the site codebase or installed dependencies, this can result in arbitrary PHP code execution.

Solution: 

Install the latest version:

  • If you use the Basket module, upgrade to Basket 2.1.17.
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Helena Zajika (helena zajika)
  • Drew Webber (mcdruid) of the Drupal Security Team
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
Kategorien: Drupal Security

Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037

13 Mai, 2026 - 19:19
Project: Date iCalDate: 2026-May-13Security risk: Critical 17 ∕ 25 AC:None/A:None/CI:All/II:None/E:Theoretical/TD:AllVulnerability: Information disclosureAffected versions: <4.0.15CVE IDs: CVE-2026-8495Description: 

This module enables you to export entity date fields as iCal feeds.

The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds.

This vulnerability is not mitigated by any permission, the routes are accessible to all anonymous users with no configuration required.

Solution: 

Install the latest version:

  • If you use the Date iCal module for Drupal 10/11, upgrade to Date iCal 4.0.15
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Joël Pittet (joelpittet)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
Kategorien: Drupal Security

Colorbox Inline - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-036

13 Mai, 2026 - 19:18
Project: Colorbox InlineDate: 2026-May-13Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <2.1.1CVE IDs: CVE-2026-8493Description: 

This module enables you to open content already on the page within a colorbox.

The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

Solution: 

Install the latest version:

  • If you use the Colorbox Inline module for Drupal 8.x, upgrade to Colorbox Inline 2.1.1
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Michael Harris (miwayha)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035

13 Mai, 2026 - 19:17
Project: Translate Drupal with GTranslateDate: 2026-May-13Security risk: Less critical 8 ∕ 25 AC:Basic/A:Admin/CI:None/II:Some/E:Theoretical/TD:UncommonVulnerability: DOM clobbering / link manipulationAffected versions: <3.0.5CVE IDs: CVE-2026-8492Description: 

The GTranslate module provides a language switcher widget for Drupal sites.

The module’s widget JavaScript did not sufficiently validate that document.currentScript referred to the executing script element. A user who can add HTML to a page could cause the generated language-switcher links to point to an unintended domain.

This vulnerability is mitigated by the fact that an attacker must be able to add HTML with attributes that are not allowed by Drupal’s default CKEditor configuration. It is also limited to sites using the paid versions of GTranslate widget JavaScript and configurations where the generated language links use script-provided values.

Solution: 

Install the latest version.

If you use the GTranslate module 3.0.x, upgrade to GTranslate 3.0.5.

Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Edvard Ananyan (edo888)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034

13 Mai, 2026 - 19:16
Project: Node View PermissionsDate: 2026-May-13Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <1.7.0 || >=2.0.0 <2.0.1CVE IDs: CVE-2026-8491Description: 

Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page
The module doesn't sufficiently handle the case where a user is cancelled and their content is reassigned to the anonymous user.
This vulnerability is mitigated by the fact that only private contents where anonymous should not have view access are affected, and only if a node was reassigned to the anonymous user.

Solution: 

Install the latest version:

  • If you use the Node View Permissions module version 2.0.0. or prior, upgrade to 2.0.1.
  • If you use the Node View Permissions module version 8.x-1.6. or prior, upgrade to 8.x-1.7.
Reported By: 
  • Adam Shepherd (adamps)
Fixed By: 
  • Bálint Nagy (nagy.balint)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security
  • « erste Seite
  • ‹ vorherige Seite
  • 1
  • 2
  • 3
  • 4

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
  • Ich brauche dringen Hilfe zu Updates oder ggf. wwie geht Composer?
  • Dynamische Ansicht von Seiteninhalt (als Tabelle?)
  • Vergabe von Berechtigungen für bestimmte Rollen; mir fehlt der Haken bzw. das „Veröffentlicht“
  • Medien und andere Daten mit Feeds von Drupal 7 auf Drupal 10 migrieren
  • Rolle erstellen nicht zu finden
  • für drupal11 ein Slider Modul
Weiter

Neue Kommentare

  • Gefunden
    vor 7 Wochen 17 Stunden
  • Vielen Dank für die ausführlichen Hinweise...
    vor 7 Wochen 4 Tagen
  • Mögliche Ursachen und nächste Schritte
    vor 7 Wochen 4 Tagen
  • Was für einen Server benutzt
    vor 10 Wochen 19 Stunden
  • Wenn die Subdomain auf
    vor 10 Wochen 2 Tagen
  • ordnerstruktur
    vor 10 Wochen 3 Tagen
  • Die Subdomain muß auf den
    vor 10 Wochen 5 Tagen
  • Verwende doch das Tag dafür,
    vor 14 Wochen 9 Stunden
  • Guckst du hier: step by step
    vor 13 Wochen 6 Tagen
  • Guckst du hier: step by step
    vor 13 Wochen 6 Tagen

Statistik

Beiträge im Forum: 250294
Registrierte User: 20542

Neue User:

  • Kupit_hiPi
  • Thomasbxh
  • Kupit_qsPi

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 32 Gäste online.

Drupal Security

  • Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099
  • External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
  • Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097
  • Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
  • Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association