Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089

Date: 
2026-July-22
CVE IDs: 
CVE-2026-15088

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16645

The Photoswipe Drupal module provides integration for the widely used PhotoSwipe lightbox library to display / zoom images in lightbox galleries using the provided image formatters.

The module didn't sufficiently check access permissions, when viewing an image using the photoswipe image gallery display formatter, in versions < 3.0.4 (Drupal 8) or < 3.2.0 (Drupal 9 / Drupal 10).

Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16644

This module enables you to retrieve and submit webform submissions via REST endpoints.

The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Security advisory coverage removed - QA Accounts - PSA-2026-07-22

Date: 
2026-July-22

QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.

Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16643

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16642

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16641

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16646

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16640

This module enables you to add autocomplete suggestions for search forms created with the Search API module.

The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.

Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16639

In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.

The module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.

This vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.

Pages

Subscribe with RSS Subscribe to Security advisories