This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The miniorange_saml module does not correctly restrict access to certain functionality intended for administrative use. This could allow unauthorized users to access functionality or modify configuration values that should only be available to privileged users.
This module enables you to manage content deletion and provides reports for identifying orphaned content.
The module doesn't sufficiently sanitize node titles when displaying the orphaned nodes report. This leads to a persistent cross-site scripting vulnerability (XSS).
This vulnerability is mitigated by the fact that an attacker must have permission to create content of a content type configured for the orphaned nodes report.
This module enables you to add key-based authentication on a per-user
basis.
The module doesn't cache per user, potentially allowing an attacker to view another user's authentication keys, if the attacker has the same permissions.
This vulnerability is mitigated by the fact that the site must have the dynamic_page_cache module enabled.
The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers.
The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability.
This vulnerability is mitigated by the fact that an attacker needs access to an account with the Access CSP reports permission to exploit the SQL Injection.
This module enables you to turn a Drupal install into the Central Authentication System (CAS) Server. It makes your database the primary location for other systems to use for authentication in a SSO environment.
The module doesn't sufficiently check the service URL used to redirect the user during logout, leading to an open redirect.
Update 2026-09-11: Increased risk score to reflect publicly documented methods for developing exploits.
This module integrates amazee.ai's AI services into Drupal, including a Postgres/pgvector vector database backend for use with Search API AI Search.
The module doesn't sufficiently sanitize filter values before using them to build SQL queries in its Postgres/pgvector backend, allowing SQL injection.
This module enables you to add dynamic caption support to PhotoSwipe image galleries.
The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.
A module to import media files into media library.
The import folder is a plain textfield with no validation. Point it at any directory the web user can read, and the importer copies every file whose extension matches a selected media type into the public files directory and publishes it as a Media entity. Files that were deliberately kept outside the webroot, such as a private file store, become downloadable by anonymous visitors at a predictable URL.
This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports > Mail log.
The module doesn't sufficiently redact the content of the emails it logs. Account related emails are stored with their one-time login links intact, so any user who can view the log can obtain a one-time login link for any account, including user 1, and use it to log in as that account.
This islandora_advanced_search sub module enables AJAX updates for advanced search, facet, and search result blocks.
The module doesn't sufficiently check block access when arbitrary block ID's are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.
This module enables you to add an extra layer of verification for user registration.
The module doesn't sufficiently filter user-supplied input before output, resulting in an unauthenticated reflected Cross-site Scripting (XSS) vulnerability.
This module enables you to automatically translate entities.
The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities
This submodule AI Translate enables you to automatically translate entities.
The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities
This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website.
The module doesn't sufficiently sanitize for cross site scripting (XSS) when using the structured results using legacy agent setups.
This vulnerability is mitigated by the fact that an attacker must be able to invoke a prompt injection set via editorial content and the site must have been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon configuration. Any configuration setup or updated after these minor versions are not affected.
This module enables AJAX updates for advanced search, facet, and search result blocks.
The module doesn’t sufficiently check block access when arbitrary block IDs are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.
This vulnerability is mitigated by the fact that an attacker must know or guess a restricted block’s machine ID, and the block must contain sensitive content protected by block access or visibility restrictions.
This module enables you to create one or more multisites with highly granular page permissions.
The module doesn't sufficiently sanitize HTML code contained in the page name when displayed in the built-in tree browser. This results in a cross-site scripting vulnerability that may allow attackers to execute arbitrary JavaScript in the context of the user’s session.
This vulnerability is mitigated by the fact that an attacker must have the ability to create pages whose page title supports HTML.
This module enables users to authenticate using LDAP or Active Directory credentials.
The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.
The Entity PDF module can create a PDF from any entity based on any View mode.
This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.
The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata.
The 2.x version of the module does not sufficiently restrict access to API credentials in JavaScript settings. When AI agent features are enabled, the token is exposed to all page visitors (including anonymous users) via drupalSettings.
This module enables you to disable access to the /user/login form unless a secret key is provided.
The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may remain accessible until caches are cleared. An attacker may continue to access the login page despite the restriction having been enabled.
The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic blocks on a display.
The route did not check whether the requester was a signage device, nor whether the requested block was one that the module delivers to displays. As a result, an anonymous visitor could read the rendered content of blocks they were not meant to see.
This vulnerability is mitigated by the fact that many block plugins perform their own access checks on the content they display, which limits what can be disclosed through this route.
This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.
The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.
The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted.
A site administrator might inadvertently grant this permission to less-trusted users. This would allow those users to execute Twig within email templates, and to gain access to functionality and information intended only for highly trusted administrators.
This module integrates Drupal Commerce with the CyberSource payment gateway.
The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.
This issue only affects the Secure Acceptance Hosted Checkout gateway integration.
This module enables site administrators to require CAPTCHA confirmation on specific pages.
The module does not sufficiently validate its CAPTCHA verification cookies. Under certain circumstances, an unauthenticated user or automated bot can forge the cookie and bypass CAPTCHA verification entirely.
This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode.
The module does not consistently check entity view access. If a user has access to a Blazy-enabled text format, this allows them to render a field from an entity they are not permitted to view.
The issue is mitigated by the fact that the shortcode does not expose the entire entity. Only fields that the shortcode can render are vulnerable.
The Address Suggestion module provides address autocomplete functionality using configured address providers.
The module doesn't sufficiently sanitize address suggestion data returned by configured providers, which can lead to a cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must be able to inject malicious content into data returned by a configured address provider, and a user must perform a search that returns the malicious suggestion.
This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance.
The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant for node tabs and block plugins, and performed no access check for reusable custom blocks. Content that should have been denied was therefore rendered — for example, an unpublished node or unpublished reusable custom block could be shown to users without permission to view it.
This module enables you to authenticate Drupal users against external identity providers.
The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database collation configurations.
This vulnerability is minimally mitigated by the fact that it affects only sites using impacted MySQL or MariaDB collation settings for the module’s authentication mapping storage. Affected collations are quite common so all sites are encouraged to upgrade.
This module enables you to pay for Commerce transactions using Paypal.
The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment.
This vulnerability only affects sites using the Payflow Link payment gateway.
The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.
The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.
The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.
This module provides formatters to allow in-place editing in a View or other display (full content, teaser...).
The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission".