Microsoft Entra ID SSO Login - Critical - Access bypass - SA-CONTRIB-2026-005

Project machine name: 
social_auth_entra_id
Date: 
2026-January-14
CVE IDs: 
CVE-2026-0948

This module enables Drupal sites to authenticate users via Microsoft Entra ID (formerly Azure AD) using OAuth 2.0.

The module doesn't sufficiently validate API responses from Microsoft allowing complete account takeover of any user, including site administrators, without requiring any credentials or access to the target's email account.

AT Internet Piano Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-004

Project machine name: 
pianoanalytics
Date: 
2026-January-14
CVE IDs: 
CVE-2026-0947

This module integrates the AT Internet Piano Analytics service.

The module does not filter administrator-entered text leading to a persistent Cross-site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer pianoanalytics".

AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003

Project machine name: 
atsmarttag
Date: 
2026-January-14
CVE IDs: 
CVE-2026-0946

This module integrates the AT Internet SmartTag service.

The module does not filter administrator-entered text leading to a persistent Cross-site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer atsmarttag".

Role Delegation - Moderately critical - Access bypass - SA-CONTRIB-2026-002

Project machine name: 
role_delegation
Date: 
2026-January-14
CVE IDs: 
CVE-2026-0945

This module allows site administrators to grant specific roles the authority to assign selected roles to users, without them needing the "administer permissions" permission.

The module contains an access bypass vulnerability when used in combination with the Views Bulk Operations module. A user with the ability to delegate a role is also able to assign the administrator role, including to their own user.

This vulnerability is mitigated by the fact that an attacker must have access to a view of users with the Views Bulk Operations module enabled.

Group invite - Moderately critical - Access bypass - SA-CONTRIB-2026-001

Project machine name: 
ginvite
Date: 
2026-January-14
CVE IDs: 
CVE-2026-0944

This module enables allows group managers to invite people into their group.

The module doesn't sufficiently check access under certain circumstances, allowing unauthorized users to access the group's content.

This vulnerability is mitigated by the fact that it only occurs when certain uncommon actions are taken by a user with the permission to create group invites.

HTTP Client Manager - Less critical - Information disclosure - SA-CONTRIB-2025-126

Project machine name: 
http_client_manager
Date: 
2025-December-17
CVE IDs: 
CVE-2025-14840

Http Client Manager introduces a new Guzzle based plugin which allows you to manage HTTP clients using Guzzle Service Descriptions via YAML, JSON or PHP files, in a simple and efficient way. The modules allows administrators to configure HTTP requests as part of Event Condition Action (ECA) automation.

The module does not sufficiently maintain separation of data from request operations, potentially leading to information disclosure in very uncommon situations.

Acquia Content Hub - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-125

Project machine name: 
acquia_contenthub
Date: 
2025-December-10
CVE IDs: 
CVE-2025-14472

This module provides a centralized content distribution and syndication solution so thta customers can publish, reuse, and syndicate content across a network of Drupal websites.

The module doesn't sufficiently protect export routes from cross-site request forgery (CSRF) attacks, potentially allowing an attacker to trick an admin into exporting an unwanted entity.

Disable Login Page - Critical - Access bypass - SA-CONTRIB-2025-124

Project machine name: 
disable_login
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13986

This module enables you to disable the standard Drupal login form (/user/login) so site owners can prevent interactive logins via the UI.

The module does not sufficiently block authentication when the REST/HTTP login route is used. An attacker (or legitimate user) with valid credentials can authenticate using the REST login endpoint (/user/login?_format=json) or other HTTP-based authentication routes, effectively bypassing the module’s protection of the UI login page.

Entity Share - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-123

Project machine name: 
entity_share
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13985

This module enables you to deploy content from one Drupal website to another.

The module provides some default configuration without sufficient access control.

This vulnerability is mitigated by the fact that an administrator can add some default access control permission.

Next.js - Critical - Access bypass - SA-CONTRIB-2025-122

Project machine name: 
next
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13984

This module enables integration between Next.js and Drupal for headless CMS functionality.

When installed, the module automatically enables cross-origin resource sharing (CORS) with insecure default settings (Access-Control-Allow-Origin: *), overriding any services.yml CORS configuration. This allows any origin to make cross-origin requests to the site without administrator knowledge or consent.

This vulnerability affects all installations as there are no configuration options to disable this behavior.

Tagify - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-121

Project machine name: 
tagify
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13983

This module enables you to use the Tagify library to enhance text input fields with tag-style UI elements.

The module does not sufficiently sanitize the infoLabel value under certain configurations, which can result in a cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that only uncommon module configurations expose the affected infoLabel output, and an attacker must have user-level access to supply or manipulate this value.

Login Time Restriction - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2025-120

Project machine name: 
login_time_restriction
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13982

This module enables you to apply time-based login restrictions and display related warning or logout confirmation pages.

The module doesn't sufficiently protect its confirmation routes from cross-site request forgery (CSRF), allowing the logout confirmation route to be triggered without user interaction.

AI (Artificial Intelligence) - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-119

Project machine name: 
ai
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13981

This modules provides the ability to chat with an AI Agent using a large-language model (LLM) provider for different purposes.

The module doesn’t sufficiently filter LLM responses. This leads to a cross-site scripting (XSS) vulnerability where an attacker can use prompt injections on user-generated content with the LLM as context.

CKEditor 5 Premium Features - Moderately critical - Access bypass - SA-CONTRIB-2025-118

Project machine name: 
ckeditor5_premium_features
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13980

The module provides instant integration of the official CKEditor 5 Premium plugins into the Drupal editor configuration.

This module has a path traversal vulnerability, which allows an access bypass to restricted image files in the system.

This access bypass is possible for any account with a View published content permission, but the risk is mitigated by the fact that only images can be opened.

Mini site - Moderately critical - Cross-Site Scripting - SA-CONTRIB-2025-117

Project machine name: 
minisite
Date: 
2025-December-03
CVE IDs: 
CVE-2025-13979

This module allows uploading a zip file and extracting its content in the public file directory to serve this content from a Drupal website.

These zip files may contain arbitrary HTML or SVG content that could allow cross-site scripting vulnerabilities. While this is an expected feature, the module does not sufficiently restrict this functionality to trusted users with a "restricted access" permission. Users without a restricted permission should not be able to inject arbitrary JavaScript.

Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008

Project machine name: 
drupal
Date: 
2025-November-12
CVE IDs: 
CVE-2025-13083

The core system module handles downloads of private and temporary files. Contrib modules can define additional kinds of files (schemes) that may also be handled by the system module.

In some cases, files may be served with the HTTP header Cache-Control: public when they should be uncacheable. This can lead to some users getting cached versions of files with information they should not be able to access. For example, files may be cached by Varnish or a CDN.

Drupal core - Moderately critical - Defacement - SA-CORE-2025-007

Project machine name: 
drupal
Date: 
2025-November-12
CVE IDs: 
CVE-2025-13082

By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.

The defacement is not stored and is only present when the URL has been crafted for that purpose. Only the defacement is present, so no other site content (such as branding) is rendered.

Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006

Project machine name: 
drupal
Date: 
2025-November-12
CVE IDs: 
CVE-2025-13081

Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.

It is not directly exploitable.

Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005

Project machine name: 
drupal
Date: 
2025-November-12
CVE IDs: 
CVE-2025-13080

Drupal Core has a rarely used feature, provided by an underlying library, which allows certain attributes of incoming HTTP requests to be overridden.

This functionality can be abused in a way that may cause Drupal to cache response data that it should not. This can lead to legitimate requests receiving inappropriate cached responses (cache poisoning).

This could be exploited in various ways:

Simple multi step form - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-116

Project machine name: 
simple_multistep
Date: 
2025-November-05
CVE IDs: 
CVE-2025-12761

This module provides the ability to convert any entity form into a simple multi-step form.

The module doesn’t sufficiently filter certain user-provided text leading to a cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer node form display”.

Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-115

Project machine name: 
email_tfa
Date: 
2025-November-05
CVE IDs: 
CVE-2025-12760

The Email TFA module provides additional email-based two-factor authentication for Drupal logins.

In certain scenarios, the module does not fully protect all login mechanisms as expected.

This issue is mitigated by the fact that an attacker must already have valid user credentials (username and password) to take advantage of the weakness.

Normal Drupal core security window rescheduled for November 12, 2025 due to DrupalCon - PSA-2025-11-03

Date: 
2025-November-03

The upcoming Drupal core security release window has been rescheduled from November 19, 2025 to November 12, 2025. As normal, the window will occur between 1600 UTC and 2200 UTC.

Simple OAuth (OAuth2) & OpenID Connect - Critical - Access bypass - SA-CONTRIB-2025-114

Project machine name: 
simple_oauth
Date: 
2025-October-29
CVE IDs: 
CVE-2025-12466

This module introduces an OAuth 2.0 authorization server, which can be configured to protect your Drupal instance with access tokens, or allow clients to request new access tokens and refresh them.

The module doesn't sufficiently respect granted scopes, it affects all access checks that are based on roles. For example: routes that have the _role requirement, can be bypassed with an access token.

CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-113

Project machine name: 
civictheme
Date: 
2025-October-22
CVE IDs: 
CVE-2025-12083

CivicTheme is a design system and theme framework used to build content-rich Drupal websites. It includes editorial workflows, structured content types, and flexible theming components.

CivicTheme does not sufficiently filter field data before rendering them in Twig templates. This combined with multiple instances of the Twig raw filter throughout CivicTheme components, allows for the injection of malicious scripts in browser contexts.

CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025-112

Project machine name: 
civictheme
Date: 
2025-October-22
CVE IDs: 
CVE-2025-12082

CivicTheme is a design system and theme framework used to build content-rich Drupal websites. It includes editorial workflows, structured content types, and flexible theming components.

The theme doesn't sufficiently check access to entities when they are displayed as reference cards used in manual lists, which leads to an information disclosure vulnerability

Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111

Project machine name: 
reverse_proxy_header
Date: 
2025-September-24
CVE IDs: 
CVE-2025-10929

This module allows you to specify an HTTP header name to determine the client's IP address.

The module doesn't sufficiently handle all cases under the scenario if Drupal Core settings $settings['reverse_proxy'] is set to TRUE and $settings['reverse_proxy_addresses'] is configured.

This vulnerability allows an attacker to spoof a request IP address (as Drupal sees it), potentially bypassing a variety of controls.

Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110

Project machine name: 
currency
Date: 
2025-September-24
CVE IDs: 
CVE-2025-10930

This module allows you to use different currencies on your website and do currency conversion.

The module doesn't sufficiently protect routes used to enable and disable currencies from Cross-Site Request Forgery (CSRF) attacks, potentially allowing an attacker to trick an admin into changing settings.

Umami Analytics - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-109

Project machine name: 
umami_analytics
Date: 
2025-September-24
CVE IDs: 
CVE-2025-10931

This module enables you to add Umami Analytics web statistics tracking system to your website.

The "administer umami analytics" permission allows inserting an arbitrary JavaScript file on every page. While this is an expected feature, the permission lacks the "restrict access" flag, which should alert administrators that this permission is potentially dangerous and can lead to cross-site scripting (XSS) vulnerabilities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer umami analytics”.

Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108

Project machine name: 
access_code
Date: 
2025-September-24
CVE IDs: 
CVE-2025-10928

This module enables users to sign in with an access code instead of entering user names and passwords. When users are allowed to pick their own access codes, they can guess other users' access codes based on the fact that access codes need to be unique and the system warns if the code of their choice is taken.

This vulnerability is mitigated by the fact that an attacker must have a role with the "change own access code" permission.

Plausible tracking - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-107

Project machine name: 
plausible_tracking
Date: 
2025-September-24
CVE IDs: 
CVE-2025-10927

This module integrates Plausible Analytics on a site.

The module did not properly filter output in certain cases.

This vulnerability is mitigated by the fact that an attacker must have permission to add raw HTML to the website, such as an unfiltered WYSIWYG field on a public-facing comment.

JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106

Project machine name: 
json_field
Date: 
2025-September-24
CVE IDs: 
CVE-2025-10926

This module enables you to store and display JSON data using optional 3rd party libraries.

The module doesn't sufficiently filter data using some of the included field formatters leading to a Cross-site Scripting (XSS) vulnerability.

Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105

Project machine name: 
acquia_dam
Date: 
2025-September-03
CVE IDs: 
CVE-2025-9954

This module enables you to connect a Drupal site to the Acquia DAM service, which syncs media from the third party service to the site.

The module doesn't sufficiently validate authorization to a list of DAM assets currently synced to the website creating an access bypass vulnerability.

This vulnerability is mitigated by the fact that it only impacts sites where users having the “view media” permission accessing any DAM asset is undesirable.

Owl Carousel 2 - Critical - Unsupported - SA-CONTRIB-2025-104

Project machine name: 
owlcarousel2
Date: 
2025-August-27
CVE IDs: 
CVE-2025-9554

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

API Key manager - Critical - Unsupported - SA-CONTRIB-2025-103

Project machine name: 
api_key_manager
Date: 
2025-August-27
CVE IDs: 
CVE-2025-9553

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Synchronize composer.json With Contrib Modules - Critical - Unsupported - SA-CONTRIB-2025-102

Project machine name: 
sync_composer_with_contrib
Date: 
2025-August-27
CVE IDs: 
CVE-2025-9552

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Protected Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-101

Project machine name: 
protected_pages
Date: 
2025-August-27
CVE IDs: 
CVE-2025-9551

This module enables you to protect individual pages with a password.

The module doesn't limit the number of password attempts, making it vulnerable to brute force attacks.

This vulnerability is mitigated by the fact that an attacker must know the protected page's URL.

CVSS risk score (experimental) 6.3 / Medium

Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100

Project machine name: 
facets
Date: 
2025-August-27
CVE IDs: 
CVE-2025-9550

This module enables you to to easily create and manage faceted search interfaces.

The module doesn’t sufficiently filter certain user-provided text leading to a cross site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer facets”.

CVSS risk score (experimental) 4.8 / Medium

Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099

Project machine name: 
facets
Date: 
2025-August-27
CVE IDs: 
CVE-2025-9549

This module enables you to to easily create and manage faceted search interfaces.

The module doesn't sufficiently check access to entities when they are displayed as facets.

This vulnerability is mitigated by the fact that only sites that show facets with entity labels (like taxonomy terms) are affected, and only if some of those entities are unpublished or have other access restrictions.

CVSS risk score (experimental) 6.9 / Medium

Authenticator Login - Moderately critical - Access bypass - SA-CONTRIB-2025-098

Project machine name: 
alogin
Date: 
2025-August-27
CVE IDs: 
CVE-2025-8093

This module allows users to setup two-factor authentication (2FA) using authenticator apps for enhanced login security.

The module did not protect all possible login paths provided by core modules.

CVSS risk score (experimental) 6.3 / Medium

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Layout Builder Advanced Permissions - Moderately critical - Access bypass - SA-CONTRIB-2025-097

Project machine name: 
layout_builder_perms
Date: 
2025-August-13
CVE IDs: 
CVE-2025-8996

The Layout Builder Advanced Permissions module enables you to have fine grained control over who can do what in editing pages built with Layout Builder.

The module doesn't sufficiently control access for adding sections in the submodule.

This vulnerability is mitigated by the fact that an attacker must have a role with a specific set of permissions:

Authenticator Login - Highly critical - Access bypass - SA-CONTRIB-2025-096

Project machine name: 
alogin
Date: 
2025-August-13
CVE IDs: 
CVE-2025-8995

This module enables users to setup two-factor authentication (2FA) using authenticator apps for enhanced login security. The module alters the standard Drupal login form to use AJAX callbacks for handling authentication flow.

The module doesn't sufficiently validate authentication under specific conditions, allowing an attacker to log in as any account where they know the username.

AI SEO Link Advisor - Less critical - Server-side Request Forgery - SA-CONTRIB-2025-095

Project machine name: 
ai_seo_link_advisor
Date: 
2025-August-06
CVE IDs: 
CVE-2025-8675

This module enables you to provide SEO analysis and recommendations for a given URL.

The module doesn't sufficiently sanitize user-supplied URLs, leading to a Server-side request forgery (SSRF) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access seo analyzer".

GoogleTag Manager - Moderately critical - Cross-site scripting - SA-CONTRIB-2025-094

Project machine name: 
gtm
Date: 
2025-July-30
CVE IDs: 
CVE-2025-8362

This module enables you to integrate Google Tag Manager (GTM) into your Drupal site by allowing administrators to configure and embed GTM container snippets.

The module doesn't sufficiently sanitize the GTM container ID under the scenario where a user with the Administer gtm permission enters malicious input into the GTM-ID field. This value is directly inserted into a <script> tag, making the site vulnerable to Cross-site Scripting (XSS) attacks.

Config Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-093

Project machine name: 
config_pages
Date: 
2025-July-30
CVE IDs: 
CVE-2025-8361

This module enables you to access an edit page for a config page.

The module doesn't sufficiently check the access permissions (hook_ENTITY_TYPE_access() wasn't taken into account).

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit ID config page" and that it only affects sites that have access restricted via the hook_ENTITY_TYPE_access() hook.

COOKiES Consent Management - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-092

Project machine name: 
cookies
Date: 
2025-July-23
CVE IDs: 
CVE-2025-8092

This module allows you to manage video media items using the COOKiES module (disabling external video elements). These elements will be enabled again, once the COOKiES banner is accepted.

The module doesn't sufficiently check whether to convert "data-src" attributes to "src" when their value might contain malicious content under the scenario, that module specific classes are set on the HTML element.

Real-time SEO for Drupal - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-091

Project machine name: 
yoast_seo
Date: 
2025-July-16
CVE IDs: 
CVE-2025-7716

This module enables you to analyze the content that you're authoring for a website. It shows you a preview of what a search result might look like.

The module doesn't sufficiently escape the metadata from content while rendering the preview, opening up the possibility of a XSS attack.

This vulnerability is mitigated by the fact that an attacker must be able to author content that is analyzed by the Real-Time SEO module.

Block Attributes - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-090

Project machine name: 
block_attributes
Date: 
2025-July-16
CVE IDs: 
CVE-2025-7715

This module allows you to define custom attributes for a block. You can specify an attribute name to be added to the block in a predefined format.

The module does not sufficiently validate the provided attributes, which makes it possible to insert JavaScript event attributes such as onmouseover, onkeyup, etc. These attributes can execute JavaScript code when the page is rendered, leading to cross-site scripting (XSS) vulnerabilities.

File Download - Moderately critical - Access bypass - SA-CONTRIB-2025-089

Project machine name: 
file_download
Date: 
2025-July-16
CVE IDs: 
CVE-2025-7717

The File Download enables you to allow users to download file and image entities directly using a custom field formatter. It also provides an optional submodule to count and display file downloads in Views, similar to how the core statistics module tracks content views.

The File Download module does not properly validate input when handling file access requests. This can allow users to bypass protections and access private files that should not be publicly available.

Mail Login - Critical - Access bypass - SA-CONTRIB-2025-088

Project machine name: 
mail_login
Date: 
2025-July-09
CVE IDs: 
CVE-2025-7393

This module enables users to login by email address with the minimal configurations.

The module included some protection against brute force attacks on the login form, however they were incomplete. An attacker could bypass the brute force protection allowing them to potentially gain access to an account.

Pages

Subscribe with RSS Subscribe to Security advisories