Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by a community member. These posts by the Drupal security team are also sent to the security announcements e-mail list.

SA-CONTRIB-2012-018 - Revisioning - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-018
  • Project: Revisioning (third-party module)
  • Version: 6.x
  • Date: 2012-FEB-08
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-017 - Finder - Multiple vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-017
  • Project: Finder (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-February-08
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Arbitrary PHP code execution, Multiple vulnerabilities
Read more

SA-CONTRIB-2012-016 - Forward module CSRF and Access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-016
  • Project: Forward (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-February-01
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, Cross Site Request Forgery
Read more

SA-CONTRIB-2012-015 - Managesite - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-015
  • Project: Managesite (third-party module)
  • Version: 6.x
  • Date: 2012-January-25
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-014 - Drupal Commerce - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-014
  • Project: Drupal Commerce (third-party module)
  • Version: 7.x
  • Date: 2012-January-25
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-013 - Search Autocomplete - SQL Injection

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-013
  • Project: Search Autocomplete (third-party module)
  • Version: 7.x
  • Date: 2012-January-25
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection
Read more

SA-CONTRIB-2012-012 - Quicktabs - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-012
  • Project: Quick Tabs (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-January-18
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-011 - Panels - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-011
  • Project: Panels (third-party module)
  • Version: 6.x
  • Date: 2012-January-18
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-010 - stickynote - Multiple vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-010
  • Project: stickynote (third-party module)
  • Version: 7.x
  • Date: 2012-January-17
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery
Read more

SA-CONTRIB-2012-009 - Revisioning - Access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-009
  • Project: Revisioning (third-party module)
  • Version: 7.x
  • Date: 2012-January-18
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Read more
Subscribe with RSS Syndicate content

Security announcements

All security announcements are posted to an email list as well. Once logged in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.

You can also get rss feeds for core, contrib, or public service announcements or follow @drupalsecurity on twitter.

Contacting the Security Team

In order to report a security issue, or to learn more about the security team, please see the Security team handbook page.

Writing Secure Code

If you are a Drupal developer, please read the handbook section on Writing secure code.

There are many useful books about Drupal. Here are two that discuss security:

Advertising helps build a successful ecosystem around Drupal.
nobody click here