Critical · 2,587 sites report using it · SA-CONTRIB-2026-018 · on drupal.org
This module allows users to log in to a website using a single sign on service.
The module does not properly clean user input. Someone could use this to uncover private details or alter existing information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate SAML SSO - Service Provider to 3.1.3.
For developers: what the fix changed
The fix sanitises the status code parameter using Xss::filter in the showErrorMessage method of src/MiniOrangeSamlAcs.php.
3.1.2 to 3.1.3 1 commit, 1 file.
src/MiniOrangeSamlAcs.php +5 −3 fix
Full diff, 3.1.2 to 3.1.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 244,414 sites report using it · SA-CONTRIB-2026-015 · on drupal.org
This module protects web forms from automated spam by requiring visitors to pass a test.
The module does not properly cancel security tokens after they are used. Someone could use this to bypass the spam protection on future form submissions. They could not view or alter any hidden information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker manually solves at least one spam test to collect valid tokens.
- Has it been used in attacksYes. It has been used in real attacks.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CAPTCHA to 8.x-1.17 or 2.0.10, whichever branch you are on.
For developers: what the fix changed
The fix prevents CAPTCHA replay attacks by invalidating the session token (setting it to NULL) upon successful validation in `captcha_validate()` within `captcha.module`, and prevents retrieving solutions for already solved sessions. It also regenerates the token for 'show always' persistence in `src/Element/Captcha.php`.
Also in this release The release also includes test fixes, removes the VERSION key from libraries.yml, adds a data-nosnippet attribute to the CAPTCHA template, and makes minor accessibility and logging improvements.
8.x-1.16 to 8.x-1.17 10 commits, 13 files including 6 tests.
.gitlab-ci.yml +2 −2
captcha.inc +4 −0
captcha.module +37 −29 fix
modules/image_captcha/image_captcha.libraries.yml +0 −3
modules/image_captcha/js/image_captcha_refresh.js +1 −1
src/Element/Captcha.php +15 −0 fix
templates/captcha.html.twig +11 −9
Full diff, 8.x-1.16 to 8.x-1.17 · Full diff, 2.0.9 to 2.0.10
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 21,452 sites report using it · SA-CONTRIB-2026-013 · on drupal.org
This module improves the interface for selecting categories on a website.
The module does not properly clean user input before displaying it. Someone could use this to run malicious scripts in the browser when creating or editing a piece of content. They could uncover private details and manipulate website records.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Tagify to 1.2.49.
For developers: what the fix changed
The fix sanitises user input by wrapping variables with Drupal.checkPlain in js/tagify.js. This prevents arbitrary JavaScript execution by escaping values in functions such as highlightMatchingLetters, entityIdMarkup, and tagTemplate.
1.2.48 to 1.2.49 1 commit, 1 file.
Full diff, 1.2.48 to 1.2.49
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 11,747 sites report using it · SA-CONTRIB-2026-017 · on drupal.org
This module allows people to design and build a website directly in their browser.
The module does not properly clean data sent in certain requests. Someone could use this to discover hidden system details. They could not alter any information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if the hidden artificial intelligence sub module is enabled and an attacker has an account with the access right to use it.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Drupal Canvas to 1.1.1.
For developers: what the fix changed
The fix updates CanvasBuilder.php to strictly validate that the provided file source is a base64 encoded JPEG or PNG data URI and uses base64_decode instead of file_get_contents, preventing server side request forgery.
1.1.0 to 1.1.1 1 commit, 1 file.
modules/canvas_ai/src/Controller/CanvasBuilder.php +3 −4 fix
Full diff, 1.1.0 to 1.1.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 10,758 sites report using it · SA-CONTRIB-2026-019 · on drupal.org
This module adds browser tab icons generated by an external service to a website.
The module does not filter text entered by an administrator. Someone could use this to view restricted information or modify website records.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youA site is affected if an attacker has an account with the access right to administer responsive favicons.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Responsive Favicons to 2.0.2.
For developers: what the fix changed
The fix adds the restrict access flag to the administer responsive favicons permission in responsive_favicons.permissions.yml to mitigate the cross site scripting vulnerability by warning that the permission is for trusted users only.
2.0.1 to 2.0.2 1 commit, 1 file.
responsive_favicons.permissions.yml +1 −0 fix
Full diff, 2.0.1 to 2.0.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 6,783 sites report using it · SA-CONTRIB-2026-014 · on drupal.org
This module blocks automated bots using a firewall.
The module does not properly clean user input. Someone could use this to reveal protected information or manipulate website content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if a visitor is challenged or blocked by the firewall.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Anti-Spam by CleanTalk to 9.7.0.
For developers: what the fix changed
The fix sanitises the `$request_uri` variable using `htmlspecialchars` in `lib/Cleantalk/Common/Firewall/Modules/Sfw.php` to prevent reflected XSS when users are challenged by the firewall.
Also in this release The release also includes fixes for duplicated cookie settings, PostgreSQL database support improvements, and various code formatting updates.
9.6.1 to 9.7.0 35 commits, 43 files including 1 test.
.gitlab-ci.yml +2 −1
cleantalk.module +19 −5
composer.json +2 −2
js/apbct-public.js +7 −1
lib/Cleantalk/Common/Antispam/Cleantalk.php +13 −0
lib/Cleantalk/Common/Db/Db.php +138 −138
lib/Cleantalk/Common/Db/DbTablesCreator.php +7 −7
lib/Cleantalk/Common/Firewall/FirewallUpdater.php +132 −21
lib/Cleantalk/Common/Firewall/Modules/AntiCrawler.php +16 −4
lib/Cleantalk/Common/Firewall/Modules/Sfw.php +6 −4 fix
lib/Cleantalk/Common/Helper/Helper.php +2 −2
lib/Cleantalk/Common/Http/Request.php +4 −8
Full diff, 9.6.1 to 9.7.0
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 2,790 sites report using it · SA-CONTRIB-2026-011 · on drupal.org
This module allows users to add icons to the text editor.
The module does not properly check access rights for certain pages. Someone could use this to access features they should not reach. They could not view protected information but they could manipulate website content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Material Icons to 2.0.4.
For developers: what the fix changed
The fix adds a new permission in material_icons.permissions.yml and updates material_icons.routing.yml to require this permission for the dialog and autocomplete routes instead of the generic access content permission.
Also in this release The release also adds sanitisation and validation to the submitted form values in src/Form/IconDialog.php.
2.0.3 to 2.0.4 1 commit, 3 files.
material_icons.permissions.yml +4 −0 fix
material_icons.routing.yml +2 −2 fix
src/Form/IconDialog.php +9 −3
Full diff, 2.0.3 to 2.0.4
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 726 sites report using it · SA-CONTRIB-2026-016 · on drupal.org
This module connects a website to an open source digital asset management system.
The module does not properly clean web addresses used for attaching media to a piece of content. Someone could use this to access private files or modify website records.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an account with the access right to create media and the ability to edit the piece of content the media is attached to.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Islandora to 2.17.5.
For developers: what the fix changed
The fix adds a `validateContentLocation` method in `src/MediaSource/MediaSourceService.php` to sanitize the `Content-Location` header, preventing path traversal and ensuring it is a valid stream wrapper URI. It also introduces `determinePersistedMimeType` to securely guess the MIME type of uploaded files instead of trusting user input.
Also in this release Added automated tests to verify the new path traversal and MIME-type spoofing protections.
2.17.4 to 2.17.5 1 commit, 3 files including 1 test.
islandora.services.yml +1 −1 fix
src/MediaSource/MediaSourceService.php +93 −3 fix
Full diff, 2.17.4 to 2.17.5
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 129 sites report using it · SA-CONTRIB-2026-012 · on drupal.org
This module allows a website to display pages with different designs based on specific conditions.
The module uses insecure web requests to turn design rules on or off. Someone could trick an administrator into clicking a link to change these rules. They could not view private details but they could alter website settings.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker knows the internal system name of a design rule.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Theme Negotiation by Rules to 1.2.1.
For developers: what the fix changed
Adds CSRF token requirements to the enable and disable routes in theme_rule.routing.yml.
1.2.0 to 1.2.1 1 commit, 1 file.
theme_rule.routing.yml +2 −0 fix
Full diff, 1.2.0 to 1.2.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.