Newsfeed-Generator
Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The Webform Share submodule can expose a webform for embedding on another site.
Under certain circumstances, submissions for an Ajax-enabled Webform using Webform Share can bypass anti-spam protections.
This vulnerability is mitigated by the fact that Webform Share must be enabled, sharing must be enabled for the affected webform, and the affected webform must rely on compatible Form-API-based anti-spam protections such as Honeypot or Antibot.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Alan Dixon (adixon)
- Dan Chadwick (danchadwick)
- Jacob Rockowitz (jrockowitz)
- Liam Morland (liam morland)
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Mori Sugimoto (dokumori) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Less critical - Denial of service - SA-CONTRIB-2026-170
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Forms may be displayed in blocks.
Webform does not sufficiently validate an optional token query value before using it. Under specific configurations where a Webform is rendered for anonymous visitors, a malicious request can cause the request to consume significant resources leading to a Denial of Service.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Site builders may also configure handlers for processing submissions, including email handlers that may include uploaded files as attachments.
In affected configurations, Webform did not sufficiently validate a managed file upload element when processing a new submission. A user with access to submit a vulnerable webform could potentially access other managed files they were not authorized to view.
This vulnerability is mitigated by the fact that a site must have a Webform with a managed file upload element and a configuration that exposes submitted files, such as allowing users to view their own webform submissions or sending uploads as email attachments.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Heine Deelstra (heine) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module does not sufficiently validate requested filenames when serving generated submission exports. Under certain configurations, a user with permission to view submission results for one webform may be able to access or remove files from the configured export temporary directory that were not generated for that webform.
This vulnerability is mitigated by the fact that an attacker must have access to view submission results for a webform and must know or be able to determine a target filename.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167
The Webform module enables site builders to create forms and collect submissions.
The module does not sufficiently restrict access to configure Remote HTTP Operations handlers. This vulnerability could allow a user with permission to edit a webform to configure a remote HTTP operation.
The update adds the Administer webform remote post URLs permission. Review this permission and ensure it is granted only to trusted roles.
The vulnerability is mitigated by the fact that an attacker must have a role with permission to edit a webform.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.11.
Review the new permission Administer webform remote post URLs and ensure it is only granted to trusted roles.
Reported By:- Pierre Rudloff (prudloff) of the Drupal Security Team
- Wesley Giles (seraphdev)
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module does not sufficiently restrict access to raw webform source editing when the Webform UI module is not enabled. This could allow a user with webform creation or editing permissions to enter source configuration that is rendered unsafely.
This vulnerability is mitigated by the fact that an attacker must have permission to create or edit webforms.
Solution:Install the latest version.
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Dan Chadwick (danchadwick)
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Liam Morland (liam morland)
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Less critical - Access bypass - SA-CONTRIB-2026-165
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
When Webform is used with JSON:API enabled, submissions may be cached without varying correctly by the authenticated user. If a webform is configured so that authenticated users can view their own submissions, a request to the JSON:API webform submission collection can return a cached response generated for a different user.
This can allow an authenticated user to view another user's webform submission data through the JSON:API collection endpoint.
This vulnerability is mitigated by the fact that JSON:API must be enabled, the affected webform must expose submissions through JSON:API, and the attacker must have an account with permission to view their own submissions for the affected webform.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Juraj Nemec (poker10) of the Drupal Security Team
Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module includes a Webform Submission Export/Import submodule that allows importing submission data from uploaded CSV files or remote URLs.
The submodule did not sufficiently validate access to export/import functionality. A user who could edit webform submissions and access webform results could also access the import interface, including the remote URL import path, leading to a server-side request forgery vulnerability.
Sites that do not enable the Webform Submission Export/Import submodule are not affected.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
For sites that need remote imports, explicitly configure the trusted hosts in settings.php:
$settings['webform_submission_export_import_csv_hosts'] = ['staging.example.com']; $settings['webform_submission_export_import_file_hosts'] = ['files.staging.example.com', '*.google.com']; Reported By:- abdo.boutanos@richemont.com
- chulhan park (cjfgks1230)
- Abdulhakeem Onipede (kism37)
- Marcus Johansson (marcus_johansson)
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may add tooltips and help text to these forms.
Some Webform tooltips and help text were not sufficiently sanitized, resulting in possible cross-site scripting (XSS).
This vulnerability is mitigated by the fact that an attacker must have permission to create or edit affected Webform configuration or content.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module does not sufficiently restrict access to the custom attributes YAML editor. Users with permission to create or edit webforms (but without permission to edit webform source) may be able to add custom attributes, leading to cross-site scripting.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit webforms.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.
This vulnerability is mitigated by the fact that an attacker must have a role with create webform and edit own webform permissions, and the Webform Entity Print module must be enabled.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Cathy Theys (yesct) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Remote Post Handlers send webform data to other servers via APIs.
The module does not sufficiently filter response values from the Remote Post handler before those values are rendered through handler response tokens. If a site uses Remote Post handler response tokens in rendered output, values returned by a configured remote endpoint could be rendered as HTML, resulting in a cross-site scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must be able to control or influence the response from a configured remote endpoint, and the site must use Remote Post handler response tokens in rendered output.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module did not sufficiently sanitize attributes used by its color element. Under certain conditions, specially crafted attributes could result in cross-site scripting (XSS) when the element is rendered.
This vulnerability is mitigated by the fact that an attacker must be able to add a specially crafted link with a specific class to the same page as the affected webform.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module includes a rating element, which did not sufficiently validate its data. Under specific circumstances, this could allow cross-site scripting on a page with a rating element.
This vulnerability is mitigated by the fact that an attacker must be able to place crafted HTML markup on the same page as a Webform rating element.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module does not sufficiently sanitize text counter configuration before passing options to the bundled jQuery Text Counter library. Under certain configurations, this can allow markup from counter-related settings to be inserted into the page leading to a cross-site scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must be able to create or edit affected Webform elements, or place specially crafted counter markup on a page where the Webform counter JavaScript is active.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module provides JavaScript behaviours for announcing dynamic form updates to assistive technologies.
In some configurations, due to improper sanitisation, specially crafted announcement text could create a cross-site scripting risk for users interacting with the affected Webform.
Solution:Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jacob Rockowitz (jrockowitz)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Upcoming critical contributed project security release on September 23, 2026 - PSA-2026-09-21
- Updated 2026-09-22, 12:00 UTC, to document that the advisories in the release might be possible for more common configurations, and that other projects may have advisories.
- Updated 2026-09-21, 19:00 UTC, to document that this is not covered by Drupal Steward.
There will be a security release for a widely used contributed module on September 23, 2026 between 17:00 and 21:00 UTC.
We are announcing this release in advance because the affected contributed module is used on a significant portion of Drupal sites, and the upcoming release will include a significant number of advisories.
The advisory with the highest risk score for the release is currently rated as critical. Other, less severe advisories in the release may be accessible to anonymous users, or result from default configurations.
Other contributed projects may also release advisories on the same date, possibly with more severe vulnerabilities. Drupal core is not affected.
Drupal Steward informationThese releases will not be covered by Drupal Steward.
Advisories may be published in batches (a few at a time)The current rate of advisories may require changes to our practices going forward:
- The security team may publish advisories individually, at different times inside the window.
- We will try to publish batches grouped by module.
- We will announce in Slack when all planned releases for the day are complete.
- We will release mailing list emails about the security updates together at the end of the window, to reduce the risk of site owners updating multiple times while advisories are still being published.
These changes are intended to make the process easier for the team and to make communication from the team easier to follow.
No special release proceduresThe planned update does not require special release procedures.
Solution:Update, 2026-09-23 18:30 UTC: The Webform project has released the below 20 advisories today. Make note of the critical advisory SA-CONTRIB-2026-175, which has slightly increased severity than was originally noted in this public service announcement.
Other advisories than those below were published for other projects, so site owners should follow all normal update procedures.
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155
- (Advisory numbers 156 and 157 were accidentally skipped in how we applied the numbering; these are not missing security advisories.)
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
- Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
- Webform - Less critical - Access bypass - SA-CONTRIB-2026-165
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169
- Webform - Less critical - Denial of service - SA-CONTRIB-2026-170
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171
- Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
- Webform - Less critical - Access bypass - SA-CONTRIB-2026-173
- Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
- Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Moshe Weitzman (moshe weitzman) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013
The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal.
Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisory:
Solution:Install the latest version:
Drupal 11
- If you use Drupal 11.4.x, update to Drupal 11.4.7.
- If you use Drupal 11.3.x, update to Drupal 11.3.17.
- Drupal 11.2.x and below are end-of-life and do not receive security coverage.
Drupal 10
- If you use Drupal 10.6.x, update to Drupal 10.6.17.
- Drupal 10.5.x and below are end-of-life and do not receive security coverage.
Note that Drupal 8 and Drupal 9 have both reached end-of-life.
Instructions for contributed modulesSite owners should also review their site following the protocol for managing external libraries and plugins, as contributed projects may use additional CKEditor plugins not packaged in Drupal core.
CKEditor has also released another CVE in today's release that does not affect Drupal, but may affect custom plugins or other usecases:
Reported By: Fixed By:- catch (catch) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Mohit Aghera (mohit_aghera), provisional member of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- catch (catch) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153
The Ultimate Table Field module enables you to store table data in a field and edit each table cell through a dialog, using cell field plugins such as text, link, and file.
The module doesn't sufficiently protect the route that opens the cell editor dialog. The route is accessible to anonymous users, who can open the dialog for any cell type. The dialog allows uploading files to the server location.
This vulnerability is partially mitigated by the fact that only files with the pdf, doc and docx extensions are accepted.
Solution:Install the latest version and adjust permissions:
- If you use the 2.x branch of the Ultimate Table Field module , upgrade to Ultimate Table Field 2.0.1.
- If you use the 1.x branch of the Ultimate Table Field module , upgrade to Ultimate Table Field 1.1.1.
After updating, grant the new permission Use the Ultimate Table Field cell editor to every role that edits content containing an Ultimate Table field. Without it, editors can no longer open the cell editor dialog.
Releases of the 1.0.x branch are not supported and do not receive security coverage. Upgrade to 1.1.1 or 2.0.1.
Reported By: Fixed By: Coordinated By:- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152
This module adds automatic highlighting of taxonomy terms in content.
The module doesn't sufficiently check access on taxonomy terms. As a result, anonymous users can view any of the site's taxonomy terms at the module's JSON endpoint, including taxonomy terms that are unpublished or otherwise restricted.
Solution:Install the latest version:
- If you use the Taxonomy Term Glossary module, upgrade to term_glossary 4.6.0.
The 4.4.x and 4.5.x branches are no longer supported.
Reported By: Fixed By: Coordinated By:- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team

Neue Kommentare
vor 2 Wochen 1 Tag
vor 2 Wochen 3 Tagen
vor 2 Wochen 5 Tagen
vor 3 Wochen 1 Tag
vor 3 Wochen 1 Tag
vor 3 Wochen 1 Tag
vor 3 Wochen 1 Tag
vor 3 Wochen 4 Tagen
vor 3 Wochen 5 Tagen
vor 3 Wochen 5 Tagen