QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.
This module enables you to add autocomplete suggestions for search forms created with the Search API module.
The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.
In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.
The module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.
This vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.
This module provides a better UI for managing and selecting Media entities in a folder structure.
The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.
The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.
This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.