Drupal security updates, in plain English

Week of 3 June 2026

Drupal publishes security updates on Wednesdays. This week there were 4, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Moderately critical: 4 updates

Include in your next routine update, within the month.

Commerce Core

Moderately critical · 36,470 sites report using it · SA-CONTRIB-2026-041 · on drupal.org

This module provides online shopping features for a website.

A visitor could place malicious code into the comments section of an order receipt email. They could use this to view private information or alter content when the email is read. They could not take full control of the website.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youThis applies if the website uses the checkout feature and has the customer comments section turned on.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Commerce Core to 3.3.6.

For developers: what the fix changed

The fix removes the raw filter from the customer comments output in the commerce order receipt Twig template and replaces it with the nl2br filter to ensure the output is properly escaped.

3.3.5 to 3.3.6 1 commit, 1 file.

  • modules/order/templates/commerce-order-receipt.html.twig +1 −1 fix

Full diff, 3.3.5 to 3.3.6

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Anti-Spam by CleanTalk

Moderately critical · 6,783 sites report using it · SA-CONTRIB-2026-042 · on drupal.org

This module protects website forms from automated spam messages without using puzzles.

An administrator could place malicious code on the page if they can alter the response from the spam protection service. They could use this to view private information or change content on the website. They could not take full control of the website.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youThis applies if someone can alter the response from the spam protection service through a compromised server or a man in the middle attack.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Anti-Spam by CleanTalk to 9.7.1.

For developers: what the fix changed

The fix sanitises the API response message by passing it through `_cleantalk_filter_response()` in `_cleantalk_die()` and `ct_die()` within `src/CleantalkFuncs.php`, which now uses a custom HTML sanitisation method `apbct_sanitize_custom_message()`.

Also in this release Updated the bot detector wrapper URL and added a new DTO class in the common library.

9.7.0 to 9.7.1 5 commits, 4 files.

  • cleantalk.libraries.yml +1 −1
  • lib/Cleantalk/Common/Templates/Dto.php +59 −0
  • src/CleantalkFuncs.php +78 −2 fix
  • src/EventSubscriber/RequestSubscriber.php +2 −3 fix

Full diff, 9.7.0 to 9.7.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

TacJS

Moderately critical · 1,875 sites report using it · SA-CONTRIB-2026-040 · on drupal.org

This module helps a website comply with European cookie laws.

A person with an ordinary account could place specific code on a page to delete cookies. They could use this to alter data on the website. They could not view any private information.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if a person has the access right to insert specific information into a page.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate TacJS to 8.x-6.8.

For developers: what the fix changed

The provided diff does not contain the security fix, as it only shows minor emoji updates in the language files of the tarteaucitron.js library.

The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.

Also in this release The release updated the tarteaucitron.js library to version 1.33.0 which included minor emoji updates in various language files.

8.x-6.7 to 8.x-6.8 1 commit, 81 files.

  • assets/vendor/tarteaucitron.js/.gitignore +1 −0
  • assets/vendor/tarteaucitron.js/README.md +11 −8
  • assets/vendor/tarteaucitron.js/css/tarteaucitron.css +239 −55
  • assets/vendor/tarteaucitron.js/css/tarteaucitron.min.css +0 −0
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.ar.js +1 −1
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.ar.min.js +1 −1
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.bg.js +1 −1
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.bg.min.js +1 −1
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.ca.js +1 −1
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.ca.min.js +1 −1
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.cn.js +1 −0
  • assets/vendor/tarteaucitron.js/lang/tarteaucitron.cn.min.js +1 −1

Full diff, 8.x-6.7 to 8.x-6.8

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

LocalGov Workflows

Moderately critical · 486 sites report using it · SA-CONTRIB-2026-039 · on drupal.org

This module provides a system for approving and scheduling content on a website.

A visitor could see a list of service contacts and the content assigned to them. They could view this private information but they could not change any data. They could not take full control of the website.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate LocalGov Workflows to 1.6.0.

For developers: what the fix changed

The fix updates the access permission for the localgov_content_by_owner view from access content to administer localgov_service_contact in the view configuration file and via an update hook in localgov_workflows_notifications.install.

1.5.0 to 1.6.0 1 commit, 2 files.

  • modules/localgov_workflows_notifications/config/optional/views.view.localgov_content_by_owner.yml +1 −1 fix
  • modules/localgov_workflows_notifications/localgov_workflows_notifications.install +15 −0 fix

Full diff, 1.5.0 to 1.6.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.