Drupal CMS 2.0 and Canvas in a client project

Posted by Webpro Company blog - 18 Jun 2026 at 06:00 UTC
Drupal CMS 2.0 promises a faster start, visual page building and AI-assisted workflows. In a client project, the important question is not only how good the demo looks, but how the solution behaves two years later. Drupal CMS 2.0 was released on 28 January 2026. Its main themes are Canvas, AI tools and site templates. Drupal.org describes it as a way for marketing teams to launch branded sites faster. This is an important shift for Drupal. Drupal has long been strong for complex systems, but getting started has often required more technical work than simpler CMS products. Drupal CMS is an attempt to reduce that friction. What changed in Drupal CMS 2.0? Drupal CMS 2.0 is not a separate technology branch. It is still Drupal, but with a new starting point. The main changes include: Canvas…
Categories: Planet Drupal

Why DrupalCon Rotterdam Is Worth Attending

Posted by DrupalCon News & Updates - 18 Jun 2026 at 05:32 UTC

DrupalCon Rotterdam is one of those events that naturally attracts attention across the Drupal ecosystem. Not only because it brings the community together, but because it creates a space where technology, strategy, contribution and real-world digital projects meet.

For anyone working with Drupal, open source or digital experience platforms, the question is not just “what happens at DrupalCon?”, but it might be: “If you have never been before, why should this be the year to go?”

 

Image Photo by PdJohnson

            Photo by Joris Vercammen 


Why Rotterdam?

Rotterdam feels like a strong fit for an event like DrupalCon. It is a city known for innovation, architecture, international connections and a forward-looking mindset — qualities that align naturally with the spirit of the Drupal community.

Bringing DrupalCon to Rotterdam creates an opportunity to connect the European Drupal community in a dynamic and accessible setting. It also gives professionals from different markets the chance to meet, exchange perspectives and discuss how Drupal continues to evolve in a fast-changing digital landscape.


Learning from real experience

One of the strongest reasons to attend DrupalCon is the quality of the knowledge shared by the community.

Read more

Categories: Planet Drupal

Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009

Posted by Security advisories - 17 Jun 2026 at 18:58 UTC
Project: Drupal coreDate: 2026-June-17Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Improper validationAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55808Description: 

The JSON:API and REST modules allow you to upload image files to image fields.

The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious user to upload a file that is not an image.

Certain web-server configurations may serve the uploaded file with its actual MIME type rather than an image type. This may lead to cross-site scripting (XSS) or other unexpected behavior.

Solution: 

Install the latest version:

Drupal 11

Drupal 10

Read more

Categories: Planet Drupal

Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Posted by Security advisories - 17 Jun 2026 at 18:57 UTC
Project: Drupal coreDate: 2026-June-17Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Server-side request forgeryAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55807Description: 

The Media module comes with support for oEmbed. The oEmbed specification contains two discovery mechanisms, via providers.json and via URL discovery.

The URL discovery code could be leveraged to trick Drupal into making server-side requests to any URL.

Solution: 

Install the latest version:

Drupal 11

Drupal 10

Read more

Categories: Planet Drupal

Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007

Posted by Security advisories - 17 Jun 2026 at 18:57 UTC
Project: Drupal coreDate: 2026-June-17Security risk: Less critical 9 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:DefaultVulnerability: Cache poisoning and open redirectAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55806Description: 

Drupal core ships a rebuild.php front controller that can be used to rebuild Drupal (clearing the caches and rebuilding the container) when the site is in an unexpected condition.

This script doesn't correctly check the Host header against the list of trusted host patterns. This could result in cache poisoning or a redirect to an attacker-controlled domain.

Solution: 

Install the latest version:

Drupal 11

Drupal 10

Read more

Categories: Planet Drupal

Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006

Posted by Security advisories - 17 Jun 2026 at 18:57 UTC
Project: Drupal coreDate: 2026-June-17Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Gadget chainAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55804Description: 

Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.

This issue is not directly exploitable.

This issue is mitigated by the fact that in order for it to be exploitable, a separate vulnerability must be present to allow an attacker to pass unsafe input to unserialize().

Solution: 

Install the latest version:

Drupal 11

Drupal 10

Read more

Categories: Planet Drupal

Drupal core - Critical - PHP object injection - SA-CORE-2026-005

Posted by Security advisories - 17 Jun 2026 at 18:56 UTC
Project: Drupal coreDate: 2026-June-17Security risk: Critical 18 ∕ 25 AC:None/A:User/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: PHP object injectionAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55803Description: 

SA-CORE-2019-003 added protection for fields that store serialized data to disallow direct writes via web services.

The above fix did not cover all potential attack vectors for JSON:API. An attacker with appropriate JSON:API write permission could potentially inject a malicious payload in certain rare circumstances, potentially resulting in PHP Object Injection.

This vulnerability is mitigated by the fact that in order to be exploitable:

  • A site must use an entity reference field type that stores a serialized property.
  • An attacker must have permission to write to the entity via JSON:API.

No field type shipped with Drupal core meets these criteria, and contributed or user-created field types that do appear to be extremely unusual. This update protects all such fields; no changes are required in contributed modules.

Read more

Categories: Planet Drupal

How to Integrate Google Cloud Storage with Drupal: Step-by-Step Guide

Posted by Drupal life hack's - 11 Jul 2025 at 08:49 UTC
How to Integrate Google Cloud Storage with Drupal: Step-by-Step Guide admin Fri, 07/11/2025 - 11:49
Categories: Removed posts

Object-Oriented Form API in Drupal 11

Posted by Drupal life hack's - 4 Jul 2025 at 14:09 UTC
Object-Oriented Form API in Drupal 11 admin Fri, 07/04/2025 - 17:09
Categories: Removed posts

Drupal 11.2 Hook Migration Guide: Modernize Your Module’s Hooks with Attributes

Posted by Drupal life hack's - 28 Jun 2025 at 08:27 UTC
Drupal 11.2 Hook Migration Guide: Modernize Your Module’s Hooks with Attributes admin Sat, 06/28/2025 - 11:27
Categories: Removed posts

Drupal Theming and Layout: When to Use Paragraphs, Layout Builder, or Twig Templates

Posted by Drupal life hack's - 26 Jun 2025 at 05:16 UTC
Drupal Theming and Layout: When to Use Paragraphs, Layout Builder, or Twig Templates admin Thu, 06/26/2025 - 08:16
Categories: Removed posts

Why More Indexes in MySQL Aren't Always Better

Posted by Drupal life hack's - 26 Jun 2025 at 03:09 UTC
Why More Indexes in MySQL Aren't Always Better admin Thu, 06/26/2025 - 06:09
Categories: Removed posts

How to Efficiently Load and Process 10,000 Nodes in Drupal Without Killing Performance

Posted by Drupal life hack's - 26 Jun 2025 at 02:53 UTC
How to Efficiently Load and Process 10,000 Nodes in Drupal Without Killing Performance admin Thu, 06/26/2025 - 05:53

Mastering OOP and SOLID Principles in PHP with Drupal Examples: A Complete Guide

Posted by Drupal life hack's - 23 Jun 2025 at 05:27 UTC
Mastering OOP and SOLID Principles in PHP with Drupal Examples: A Complete Guide admin Mon, 06/23/2025 - 08:27
Categories: Removed posts

Combining Tailwind CSS and Bootstrap (Radix) in a Drupal Theme: A Step-by-Step Guide

Posted by Drupal life hack's - 26 May 2025 at 10:11 UTC
Combining Tailwind CSS and Bootstrap (Radix) in a Drupal Theme: A Step-by-Step Guide admin Mon, 05/26/2025 - 13:11
Categories: Removed posts

Laravel for Drupal Developers: Comparing Eloquent and Entity API

Posted by Drupal life hack's - 10 Apr 2025 at 13:50 UTC
Laravel for Drupal Developers: Comparing Eloquent and Entity API admin Thu, 04/10/2025 - 16:50
Categories: Removed posts

Pages

Subscribe with RSS Subscribe to Drupal.org aggregator