Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by a community member. These posts by the Drupal security team are also sent to the security announcements e-mail list.

SA-CONTRIB-2013-007 User Relationships - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-007
  • Project: User Relationships (third-party module)
  • Version: 6.x, 7.x
  • Date: 2013-January-23
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2013-006 - Video - Arbitrary Code Execution

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-006
  • Project: Video (third-party module)
  • Version: 7.x
  • Date: 2013-January-23
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Arbitrary PHP code execution
Read more

SA-CONTRIB-2013-005 - Mark Complete Module - Cross Site Request Forgery (CSRF)

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-005
  • Project: Mark Complete (third-party module)
  • Version: 7.x
  • Date: 2013-January-16
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery
Read more

SA-CONTRIB-2013-004 - Live CSS - Arbitrary Code Execution

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-004
  • Project: Live CSS (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-January-16
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Arbitrary PHP code execution
Read more

SA-CONTRIB-2013-003 - RESTful Web Services - Cross site request forgery (CSRF)

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-003
  • Project: RESTful Web Services (third-party module)
  • Version: 7.x
  • Date: 2013-January-16
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery
Read more

SA-CONTRIB-2013-002 - Payment - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-002
  • Project: Payment (third-party module)
  • Version: 7.x
  • Date: 2013-January-09
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Read more

SA-CONTRIB-2013-001 - Search API - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-001
  • Project: Search API (third-party module)
  • Version: 7.x
  • Date: 2013-January-09
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-174 - Context - Information Disclosure

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-174
  • Project: Context (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-12-19
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Information Disclosure
Read more

SA-CONTRIB-2012-173 - Nodewords: Information disclosure

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-173
  • Project: Nodewords: D6 Meta Tags (third-party module)
  • Version: 6.x
  • Date: 2012-December-05
  • Security risk: Not critical
  • Exploitable from: Remote
  • Vulnerability: Information Disclosure
Read more

SA-CONTRIB-2012-172 - Zero Point - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-172
  • Project: Zero Point (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-November-28
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more
Subscribe with RSS Syndicate content

Security announcements

In addition to the news page and sub-tabs, all security announcements are posted to an email list. To subscribe to email: log in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.

You can also get rss feeds for core, contrib, or public service announcements or follow @drupalsecurity on Twitter.

Contacting the Security team

In order to report a security issue, or to learn more about the security team, please see the Security team handbook page.

Security books

There are many useful books about Drupal. Here are two that discuss security:

Advertising helps build a successful ecosystem around Drupal.
nobody click here