Drupal security updates, in plain English

Week of 13 May 2026

Drupal publishes security updates on Wednesdays. This week there were 4, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 1 update

Cyber Essentials expects a fix within 14 days. Do it this week.

Date iCal

Critical · 6,144 sites report using it · SA-CONTRIB-2026-037 · on drupal.org

This module lets a website export its calendar as a data feed and import external calendars.

A visitor without an account could view any private information on the website by looking at the calendar data feeds. They could read all hidden data on the site. They could not alter or delete any information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Date iCal to 4.0.15.

For developers: what the fix changed

The fix adds access checks for entities and fields to the feed method in src/Controller/DateIcalController.php and sanitises user input in the download method. It also strips HTML tags from the rrule field in src/DateICal.php.

Also in this release The release also fixes an issue with finding the frequency in raw RRULEs.

4.0.14 to 4.0.15 2 commits, 2 files.

  • src/Controller/DateIcalController.php +65 −11 fix
  • src/DateICal.php +1 −1 fix

Full diff, 4.0.14 to 4.0.15

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Moderately critical: 2 updates

Include in your next routine update, within the month.

Node View Permissions

Moderately critical · 12,446 sites report using it · SA-CONTRIB-2026-034 · on drupal.org

This module allows a website to set specific access rights for viewing different types of content.

A visitor without an account could read private pieces of content that belonged to deleted users. They could see this hidden information. They could not change or delete anything on the website.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youThis applies if a user account was cancelled and their private pieces of content were reassigned to visitors without an account.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Node View Permissions to 8.x-1.7 or 2.0.1, whichever branch you are on.

For developers: what the fix changed

The fix updates the node_view_permissions_node_grants function in node_view_permissions.module to ensure that the account ID is not zero before granting view own content permissions, preventing anonymous users from accessing reassigned private content.

8.x-1.6 to 8.x-1.7 1 commit, 1 file.

  • node_view_permissions.module +3 −2 fix

Full diff, 8.x-1.6 to 8.x-1.7 · Full diff, 2.0.0 to 2.0.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Colorbox Inline

Moderately critical · 9,651 sites report using it · SA-CONTRIB-2026-036 · on drupal.org

This module allows a website to display content that is already on the page inside a popup box.

A user with an account could add malicious website code by using specific data attributes. They could view or change certain restricted information on the page. They could not read or change all the data on the website.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if a user has the access right to enter website code containing specific data attributes.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Colorbox Inline to 2.1.1.

For developers: what the fix changed

The fix in js/colorbox_inline.js validates that the data-colorbox-inline attribute is a string without angle brackets and uses $(document).find() instead of passing the selector directly to jQuery to prevent cross site scripting.

Also in this release Fixed a PHPUnit deprecation for #[RunTestsInSeparateProcesses].

2.1.0 to 2.1.1 2 commits, 2 files including 1 test.

  • js/colorbox_inline.js +21 −16 fix

Full diff, 2.1.0 to 2.1.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Less critical: 1 update

Fix with the next routine update.

Translate Drupal with GTranslate

Less critical · 13,779 sites report using it · SA-CONTRIB-2026-035 · on drupal.org

This module provides a tool that translates the website into different languages.

An administrator could change the language links so that they send visitors to a different website. They could alter these links to point elsewhere. They could not view any private information.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youThis applies if a user can add website code with restricted attributes on a site using the paid version of the tool where the language links use script provided values.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this less critical. Fix it with the next routine update.

Tell your developerUpdate Translate Drupal with GTranslate to 3.0.5.

For developers: what the fix changed

The fix adds a check at the beginning of the IIFE in multiple JavaScript files (e.g., `js/dropdown.js`, `js/dwf.js`) to ensure `document.currentScript` is an instance of `HTMLScriptElement`, preventing DOM clobbering attacks.

Also in this release The release also added a language weights configuration option, switched from sessionStorage to localStorage, and added lazy loading to flag images.

3.0.4 to 3.0.5 2 commits, 15 files.

  • config/install/gtranslate.settings.yml +2 −1
  • js/dropdown.js +14 −8 fix
  • js/dwf.js +14 −21 fix
  • js/fc.js +16 −9 fix
  • js/fd.js +16 −9 fix
  • js/flags.js +16 −9 fix
  • js/float.js +15 −9 fix
  • js/fn.js +16 −10 fix
  • js/globe.js +15 −9
  • js/lc.js +15 −9
  • js/ln.js +15 −10
  • js/popup.js +15 −10

Full diff, 3.0.4 to 3.0.5

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.