Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16644

This module enables you to retrieve and submit webform submissions via REST endpoints.

The module doesn't sufficiently check the parent webform's permissions for creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Security advisory coverage removed - QA Accounts - PSA-2026-07-22

Date: 
2026-July-22

QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.

Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16643

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16642

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16641

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16646

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16640

This module enables you to add autocomplete suggestions for search forms created with the Search API module.

The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.

Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16639

In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.

The module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.

This vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.

Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080

Date: 
2026-July-22
CVE IDs: 
CVE-2026-16638

This module provides a better UI for managing and selecting Media entities in a folder structure.

The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012

Date: 
2026-July-15
CVE IDs: 
CVE-2026-55805

The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.

This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.

Pages

Subscribe with RSS Subscribe to Security advisories