Security advisories for third-party projects that are not part of Drupal core - this includes all modules, themes, and installation profiles that have been contributed by a community member. These posts by the Drupal security team are also sent to the security announcements e-mail list.

SA-CONTRIB-2012-171 - Webmail Plus - SQL injection - (unsupported)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-171
  • Project: Webmail Plus (third-party module)
  • Version: 6.x
  • Date: 2012-November-28
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection
Read more

SA-CONTRIB-2012-170 - MultiLink - Access Bypass

Read more

SA-CONTRIB-2012-169 - Email Field - Cross Site Scripting and Access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-169
  • Project: Email Field (third-party module)
  • Version: 6.x
  • Date: 2012-11-28
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Access bypass
Read more

SA-CONTRIB-2012-168 - Services - Information Disclosure

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-168
  • Project: Services (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-11-28
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Information Disclosure
Read more

SA-CONTRIB-2012-167 - Mixpanel - Cross site scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-167
  • Project: Mixpanel (third-party module)
  • Version: 6.x
  • Date: 2012-November-28
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-166 - Table of Contents - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-166
  • Project: Table of Contents (third-party module)
  • Version: 6.x
  • Date: 2012-November-14
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Read more

SA-CONTRIB-2012-165 - Chaos tool suite (ctools) - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-165
  • Project: Chaos tool suite (ctools) (third-party module)
  • Version: 6.x
  • Date: 2012-November-14
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-164 - Smiley module and Smileys module - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-164
  • Project: Smiley (third-party module)
  • Project: Smileys (third-party module)
  • Version: 6.x
  • Date: 2012-November-14
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting
Read more

SA-CONTRIB-2012-163 - User Read-Only - Permission escalation

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-163
  • Project: User Read-Only (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-November-14
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
Read more

SA-CONTRIB-2012-162 - RESTful Web Services - Cross site request forgery (CSRF)

  • Advisory ID: DRUPAL-SA-CONTRIB-2012-162
  • Project: RESTful Web Services (third-party module)
  • Version: 7.x
  • Date: 2012-November-14
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery
Read more
Subscribe with RSS Syndicate content

Security announcements

In addition to the news page and sub-tabs, all security announcements are posted to an email list. To subscribe to email: log in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.

You can also get rss feeds for core, contrib, or public service announcements or follow @drupalsecurity on Twitter.

Contacting the Security team

In order to report a security issue, or to learn more about the security team, please see the Security team handbook page.

Security books

There are many useful books about Drupal. Here are two that discuss security:

Advertising helps build a successful ecosystem around Drupal.
nobody click here