Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050

Project machine name: 
plotly_js
Date: 
2026-June-17
CVE IDs: 
CVE-2026-55810

The Plotly.js Graphing module provides a fully customizable implementation of the open source Plotly.js graphing library.

The module stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an object injection vulnerability when the data are unserialized.

Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049

Project machine name: 
flag_attendance_field
Date: 
2026-June-17
CVE IDs: 
CVE-2026-55809

The Flag attendance field module gives you the ability to add attendance by depending on Flag module.

flag_attendance_field stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an object injection vulnerability when the data are unserialized.

Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048

Project machine name: 
formatter_field
Date: 
2026-June-17
CVE IDs: 
CVE-2026-12535

The Formatter Field module provides a mechanism for specifying a formatter and formatter settings to be used for displaying a field, on a per-entity basis.

formatter_field stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an Object Injection vulnerability when the data are unserialized.

Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047

Project machine name: 
bfap_sb
Date: 
2026-June-10
CVE IDs: 
CVE-2026-11915

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Composer - Critical - Unsupported - SA-CONTRIB-2026-046

Project machine name: 
composer
Date: 
2026-June-10
CVE IDs: 
CVE-2026-11914

The security team is marking the Composer module for Drupal project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045

Project machine name: 
mothermayi
Date: 
2026-June-10
CVE IDs: 
CVE-2026-11913

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...

Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044

Project machine name: 
examples
Date: 
2026-June-10
CVE IDs: 
CVE-2026-11909

The Examples for Developers project aims to provide high-quality, well-documented API examples for a broad range of Drupal core functionality.

The "Read from a file" feature implemented by the file_example submodule can be used to expose any file that PHP can access. Therefore, the file_example sub-module is being removed from Examples for Developers until a version demonstrating file security best practices can be added back in the future. Developers who based a new module on this example should review their code for an access bypass.

Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043

Project machine name: 
tagify
Date: 
2026-June-10
CVE IDs: 
CVE-2026-11908

This module integrates the Tagify JavaScript library to enhance entity reference selection in entity reference widgets.

The module does not properly sanitise the name of parent taxonomy terms when rendering suggestions in the Tagify dropdown. This results in a cross-site scripting vulnerability that may allow attackers to execute arbitrary JavaScript in the context of the user’s session.

The vulnerability is mitigated by the fact an attacker must have a role with permission to create or edit taxonomy terms in a vocabulary.

Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042

Project machine name: 
cleantalk
Date: 
2026-June-03
CVE IDs: 
CVE-2026-10770

This module provides spam protection using the CleanTalk cloud service.

The module doesn't sufficiently sanitize API response messages before rendering them in HTML output. The _cleantalk_die() and ct_die() functions output the CleanTalk API response message directly into HTML without proper sanitization, allowing potential injection of arbitrary HTML or JavaScript.

Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041

Project machine name: 
commerce
Date: 
2026-June-03
CVE IDs: 
CVE-2026-10769

The module doesn't sufficiently sanitize customer comments in the order receipt email template; this could be exploited to achieve Cross-site Scripting (XSS).

This vulnerability is mitigated by the fact that it only affects installations with Checkout (commerce_checkout) enabled, and the "Comments" checkout pane (id: customer_comments) is explicitly used, which is disabled by default.

TacJS - Moderately critical - Improper Access Control - SA-CONTRIB-2026-040

Project machine name: 
tacjs
Date: 
2026-June-03
CVE IDs: 
CVE-2026-49977

This module enables sites to comply with the European cookie law using tarteaucitron.js.

The module doesn't sufficiently filter user-supplied markup inside of content leading to an attacker being able to delete arbitrary cookies.

This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.

LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039

Project machine name: 
localgov_workflows
Date: 
2026-June-03
CVE IDs: 
CVE-2026-10768

This module configures default editorial workflows for LocalGov Drupal content types. It provides a Drupal content moderation workflow, a content approvals dashboard, content scheduling and content preview.

The module doesn't sufficiently restrict access to a view of Service Contacts at which exposes the names and content items assigned to each Service Contact.

Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038

Project machine name: 
basket
Date: 
2026-May-27
CVE IDs: 
CVE-2026-9726

The Basket module enables e-commerce and checkout functionality for Drupal sites.

The module does not sufficiently sanitize user-supplied data before passing it to PHP's unserialize().

An attacker can supply a crafted payload and trigger PHP Object Injection. If a viable gadget chain exists in the site codebase or installed dependencies, this can result in arbitrary PHP code execution.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004

Project machine name: 
drupal
Date: 
2026-May-20
CVE IDs: 
CVE-2026-9082

Drupal core includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks.

A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks.

This vulnerability can be exploited by anonymous users.

Upcoming highly critical release on May 20, 2026 - PSA-2026-05-18

Date: 
2026-May-18

There will be a Drupal core security release for all supported branches on May 20, 2026, between 17:00 and 21:00 UTC. (To see this in your local timezone, refer to the Drupal Core Calendar.) The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days.

Not all configurations are affected. Reserve time on May 20 during the release window to determine whether your sites are affected and in need of an immediate update. Mitigation information will be included in the advisory.

We recommend updating to the latest supported patch (bugfix) release for your site's version of Drupal before May 20, so that you can address any other upgrade issues before the security window. (Recommendations for specific Drupal versions follow.)

This issue is being protected by Drupal Steward. Sites that use Drupal Steward are already protected from known attack vectors, but should upgrade in the near future in case additional attack vectors are discovered.

Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037

Project machine name: 
date_ical
Date: 
2026-May-13
CVE IDs: 
CVE-2026-8495

This module enables you to export entity date fields as iCal feeds.

The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds.

This vulnerability is not mitigated by any permission, the routes are accessible to all anonymous users with no configuration required.

Colorbox Inline - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-036

Project machine name: 
colorbox_inline
Date: 
2026-May-13
CVE IDs: 
CVE-2026-8493

This module enables you to open content already on the page within a colorbox.

The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035

Project machine name: 
gtranslate
Date: 
2026-May-13
CVE IDs: 
CVE-2026-8492

The GTranslate module provides a language switcher widget for Drupal sites.

The module’s widget JavaScript did not sufficiently validate that document.currentScript referred to the executing script element. A user who can add HTML to a page could cause the generated language-switcher links to point to an unintended domain.

Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034

Project machine name: 
node_view_permissions
Date: 
2026-May-13
CVE IDs: 
CVE-2026-8491

Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page
The module doesn't sufficiently handle the case where a user is cancelled and their content is reassigned to the anonymous user.
This vulnerability is mitigated by the fact that only private contents where anonymous should not have view access are affected, and only if a node was reassigned to the anonymous user.

Obfuscate - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-033

Project machine name: 
obfuscate
Date: 
2026-April-22
CVE IDs: 
CVE-2026-6871

This module enables you to obfuscate email addresses in content.

The module doesn't sufficiently sanitize user input via the Twig filter.

This vulnerability is mitigated by the fact that it only affects sites using the ROT13 encoding and where an attacker can enter content that is filtered using the module's Twig filter.

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003

Project machine name: 
drupal
Date: 
2026-April-15
CVE IDs: 
CVE-2026-6367

Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5.

The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross site scripting attack against another user.

Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002

Project machine name: 
drupal
Date: 
2026-April-15
CVE IDs: 
CVE-2026-6366

Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain" presents no direct threat, but is a vector that can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.

This issue is not directly exploitable.

Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001

Project machine name: 
drupal
Date: 
2026-April-15
CVE IDs: 
CVE-2026-6365

Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a cross-site scripting (XSS) vulnerability.

Orejime - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-032

Project machine name: 
orejime
Date: 
2026-April-08
CVE IDs: 
CVE-2026-6095

The IframeConsent element writes HTML attributes without escaping their value.

This module has a XSS vulnerability. If an attacker is able to write an <iframe-consent> tag, they may be able to insert arbitrary JavaScript.

SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-031

Project machine name: 
miniorange_saml
Date: 
2026-April-01
CVE IDs: 
CVE-2026-5343

This module enables you to perform SAML-protocol-based single-sign-on (SSO) on a Drupal site.

The module doesn't sufficiently block access, leading to a authentication bypass vulnerability.

Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030

Project machine name: 
autologout
Date: 
2026-March-18
CVE IDs: 
CVE-2026-4393

This module provides a site administrator the ability to log users out after a specified time of inactivity.

The module doesn't sufficiently protect its routes from cross-site request forgery (CSRF), allowing the logout route to be triggered without user interaction.

Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-029

Project machine name: 
unpublished_node_permissions
Date: 
2026-March-11
CVE IDs: 
CVE-2026-4933

This module creates permissions per node content type to control access to unpublished nodes per content type.

The module does not consistently control access for unpublished translated nodes.

AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028

Project machine name: 
ai
Date: 
2026-March-11
CVE IDs: 
CVE-2026-3573

The module and certain submodules (AI Automators, AI Translate, AI API Explorer, AI Content Suggestions) provide the ability to use an LLM to generate HTML or Markdown and preview it in a browser.

Under certain circumstances, rendering of this HTML can lead to exposing secret communications in the context of the LLM request.

OpenID Connect / OAuth client - Less critical - Access bypass - SA-CONTRIB-2026-027

Project machine name: 
openid_connect
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3532

This module enables you to use an external OpenID Connect login provider to authenticate and log in users on your site. If a user signs in with a login provider for the first time on the website, a new Drupal user will be created.

The module doesn't sufficiently validate the uniqueness of certain user fields depending on the database engine and its collation.

As a result, a user may be able to register with the same email address as another user.

This may lead to data integrity issues.

OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026

Project machine name: 
openid_connect
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3531

This module enables you to use an external OpenID Connect login provider to authenticate and log in users on your site. If a user signs in with a login provider for the first time on the website, a new Drupal user will be created.

A visitor who successfully logs in to their Identity Provider and is denied access to Drupal through custom code or a server error will maintain their session at the Identity Provider, possibly leading to access bypass situations, especially in a shared computing environment.

OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025

Project machine name: 
openid_connect
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3530

This module enables you to use an external OpenID Connect login provider to authenticate and log in users on your site. If a user signs in with a login provider for the first time on the website, a new Drupal user will be created.

The module doesn't sufficiently validate certain fields coming from the identity provider, which could lead to SSRF and information disclosures.

Google Analytics GA4 - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-024

Project machine name: 
ga4_google_analytics
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3529

The Google Analytics GA4 module enables users to add custom attributes to the script tag used to load the Google Analytics library. The module does not sufficiently sanitize these attributes.

This vulnerability is mitigated by the fact that an attacker must have a role with the "ga4 configure" (or "administer google analytics ga4 settings") permission.

Calculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023

Project machine name: 
calculation_fields
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3528

This module extends the Drupal form API adding "Calculation element" form element types, which can evaluate a maths expression. It offers webform integration.

The module doesn't sufficiently validate user input; this could be exploited to achieve Information Disclosure or Cross-site Scripting (XSS).

AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022

Project machine name: 
ajax_dashboard
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3527

AJAX Dashboard: Entity Dashboards enables you to create configurable dashboards attached to entities which include AJAX-reloading of a main content area based on inputs from a configurable set of buttons.

The module doesn't sufficiently check access on the dashboard configuration route. Unauthorized users could access the entity dashboard configuration page and either enable or disable dashboards. The affected administration page does not permit editing the configurations of the dashboards themselves.

File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-021

Project machine name: 
file_access_fix
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3526

This module moves files to and from private storage depending on the access of its owning entities.

The module does not always validate the access logic correctly, resulting in files attached to an entity not being protected in certain circumstances.

This vulnerability is mitigated by the fact that saving an entity a second time resolves the issue.

File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020

Project machine name: 
file_access_fix
Date: 
2026-March-04
CVE IDs: 
CVE-2026-3525

This module moves files to and from private storage depending on the access of its owning entities.
The module does not sufficiently incorporate the results of hook_file_download when a custom or contrib module implements that hook leading to access bypass.

Responsive Favicons - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-019

Project machine name: 
responsive_favicons
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3218

This module adds the favicons generated by realfavicongenerator.net to your Drupal site.

The module does not filter administrator-entered text, leading to a persistent Cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer responsive favicons".

SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018

Project machine name: 
miniorange_saml
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3217

This module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site.

The module doesn't sufficiently sanitize user input, leading to a reflected Cross-site scripting (XSS) vulnerability.

Drupal Canvas - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-017

Project machine name: 
canvas
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3216

This module enables you to easily theme and build an entire website using only their browser, without the need to write code beyond basic JSX and CSS. Content creators are able to compose content on any part of the page without relying on developers.

The project has a hidden sub-module, Drupal Canvas AI, which is disabled by default. It is typically enabled as a dependency by Drupal Recipes or enabled directly via deployment scripts (e.g., Drush). When the submodule is enabled, the following vulnerability is exposed.

Islandora - Moderately critical - Arbitrary file upload, Cross-site scripting - SA-CONTRIB-2026-016

Project machine name: 
islandora
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3215

This module integrates with Islandora, an open-source digital asset management (DAM) framework. Islandora integrates with various open-source services, which can be run in a distributed environment.

The module doesn't sufficiently sanitize URI paths for its custom route used for attaching media to nodes, which can also lead to cross-site scripting and other vulnerabilities.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "create media" and the ability to edit the node the media is being attached to.

CAPTCHA - Moderately critical - Access bypass - SA-CONTRIB-2026-015

Project machine name: 
captcha
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3214

This module enables you to protect web forms from automated spam by requiring users to pass a challenge.

The module doesn't sufficiently invalidate used security tokens under certain scenarios, which can lead to the CAPTCHA being bypassed on subsequent submissions.

This vulnerability is mitigated by the fact that an attacker must first successfully solve at least one CAPTCHA manually to harvest the valid tokens.

Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014

Project machine name: 
cleantalk
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3213

This module enables you to block bots by Firewall.

The module doesn't sufficiently sanitize user input leading to a reflected Cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that the vulnerable functionality is only presented to users that are "challenged" or blocked by the firewall.

Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013

Project machine name: 
tagify
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3212

This module integrates the Tagify JavaScript library to enhance taxonomy entity reference widgets.

The module does not sufficiently sanitise user-supplied input before rendering it inside JavaScript template strings within the Tagify widget. This allows arbitrary JavaScript execution in the browser when a user creates or edits content.

Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012

Project machine name: 
theme_rule
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3211

This module allows site builders to create so-called "theme_rule" config entities. These theme rules can render pages with different themes than the default when certain conditions match.

The module uses simple GET request to disable or enable theme rules, which allows attackers to disable or enable theme rules by tricking site administrators to click on links.

This vulnerability is mitigated by the fact that an attacker must know the machine name of the theme rule.

Material Icons - Moderately critical - Access bypass - SA-CONTRIB-2026-011

Project machine name: 
material_icons
Date: 
2026-February-25
CVE IDs: 
CVE-2026-3210

This module enables you to add icons to CKEditor.

The module doesn't sufficiently add custom permissions to the dialog and autocomplete routes, allowing full access to the routes in most scenarios.

UI Icons - Critical - Cross-site Scripting - SA-CONTRIB-2026-010

Project machine name: 
ui_icons
Date: 
2026-February-11
CVE IDs: 
CVE-2026-2349

This module enables you to integrate and manage icons with Drupal.

The module doesn't sufficiently sanitize user input leading to a reflected Cross-site Scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact that in order to be vulnerable, the "UI Icons for CKEditor 5" submodule must be enabled.

Note: this SA was edited after release to correct the risk score; there is no user authentication requirement.

Quick Edit - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-009

Project machine name: 
quickedit
Date: 
2026-February-11
CVE IDs: 
CVE-2026-2348

This module allows content to be edited in-place.

The module doesn't sufficiently sanitize certain image-related values during the editing process leading to a persistent Cross-site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have permission to create or edit an affected field.

Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008

Project machine name: 
login_disable
Date: 
2026-February-04
CVE IDs: 
CVE-2026-1917

The Login Disable module prevents users from logging in to your Drupal site unless they know the access key to add to the end of the login form page.
( default: http://example.com/user/login?admin )
If they provide the access key and have a specific role they can log in.

The module does not check for the access key when using the HTTP request login route. It is possible to use this route to log in without providing the access key.

Central Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007

Project machine name: 
cas_server
Date: 
2026-January-28
CVE IDs: 
CVE-2026-1554

This module enables you to turn a Drupal install into the Central Authentication System (CAS). It makes your database the primary location for other systems to use for authentication in a SSO environment.

The module doesn't sufficiently sanitize user-supplied field values configured to be included as attributes in a CAS server response.

This vulnerability is mitigated by the fact that an attacker must be authenticated, have the ability to enter XML into a user entity field, and that field be configured as a CAS Attribute source leading to an XML Element Injection vulnerability.

Drupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006

Project machine name: 
canvas
Date: 
2026-January-28
CVE IDs: 
CVE-2026-1553

This Drupal Canvas module is a new visual page builder for Drupal. You can create reusable components that match your design system, drag them onto a page, edit content in place, preview changes across multiple pages, and undo mistakes with ease.

The module doesn't sufficiently validate access to Canvas Pages when they are unpublished.

This vulnerability is mitigated by the fact that Canvas Pages don't have content moderation enabled by default, and they must be unpublished after being released, and archiving is not a feature provided by the module yet.

Pages

Subscribe with RSS Subscribe to Security advisories