Drupal security updates, in plain English

Week of 8 July 2026

Drupal publishes security updates on Wednesdays. This week there were 10, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 4 updates

Cyber Essentials expects a fix within 14 days. Do it this week.

Raw Formatter [Meta Tag Formatter]

Critical · 70 sites report using it · SA-CONTRIB-2026-077 · on drupal.org

This module formats meta tags for a website.

The project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Raw Formatter [Meta Tag Formatter]. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Commerce guest registration

Critical · 61 sites report using it · SA-CONTRIB-2026-079 · on drupal.org

This module allows guests to register on an online shop.

The project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Commerce guest registration. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Location Selector

Critical · 30 sites report using it · SA-CONTRIB-2026-072 · on drupal.org

This module allows website content to be assigned to one or more locations.

The module does not properly clean user input in one of its search filters. Anyone without logging in could use this to read any data on the site. They could also change any data on the site including code.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youThis applies if a list of content exists that uses the affected filter and accepts user input.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Location Selector to 8.x-1.3.

For developers: what the fix changed

The fix replaces string concatenation with parameterised queries in the query method of LocationSelectorFilter.php to prevent SQL injection.

8.x-1.2 to 8.x-1.3 1 commit, 1 file.

  • src/Plugin/views/filter/LocationSelectorFilter.php +8 −3 fix

Full diff, 8.x-1.2 to 8.x-1.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Clean RESTful

Critical · 3 sites report using it · SA-CONTRIB-2026-078 · on drupal.org

This module provides clean data feeds for a website.

The project has been withdrawn because of a security problem its maintainer did not fix. The details are not published. It should be treated as unsafe to keep.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.

Tell your developerRemove or replace Clean RESTful. There is no fixed version.

For developers: what the fix changed

The module has been withdrawn, so there is no fixed release to compare.

Moderately critical: 5 updates

Include in your next routine update, within the month.

UI Patterns (SDC in Drupal UI)

Moderately critical · 8,480 sites report using it · SA-CONTRIB-2026-075 · on drupal.org

This module allows site builders to use self contained design components when creating pages and layouts.

The module does not properly clean the code passed to design components. An ordinary account on the site could use this to read some restricted data and change or add some data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if an attacker can create or update content displayed by the module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate UI Patterns (SDC in Drupal UI) to 2.0.17.

For developers: what the fix changed

The fix improves markup sanitisation by escaping untrusted strings in `LinksPropType`, `StringPropType`, `FieldPropertySource`, and `TokenSource`, and by using `#plain_text` instead of `#children` with `Markup::create()` for plain strings in `SlotPropType`. It also overrides Twig's `include()` function in `TwigExtension` to return a `Markup` object for consistent trust boundaries.

Also in this release The release also refactored plugin managers, added a `no_ui` property to sources, introduced a `SourceTags` enum, and improved test performance.

2.0.16 to 2.0.17 10 commits, 128 files including 80 tests.

  • .cspell-project-words.txt +1 −0
  • .gitlab-ci.yml +4 −1
  • composer.json +3 −0
  • config/schema/ui_patterns.schema.yml +12 −1
  • config/schema/ui_patterns.sources.schema.yml +19 −0
  • modules/ui_patterns_field/src/Plugin/Derivative/UIPatternsSourceFieldPropertySourceDeriver.php +1 −1
  • modules/ui_patterns_field/src/Plugin/Field/FieldType/SourceValueItem.php +14 −1
  • modules/ui_patterns_field/src/Plugin/Field/FieldWidget/SourceComponentWidget.php +2 −1
  • modules/ui_patterns_field_formatters/config/schema/ui_patterns_field_formatters.sources.schema.yml +0 −18
  • modules/ui_patterns_views/src/Plugin/UiPatterns/Source/ViewFieldSource.php +0 −1
  • modules/ui_patterns_views/src/Plugin/UiPatterns/Source/ViewRowsSource.php +1 −1
  • src/Attribute/Source.php +4 −0

Full diff, 2.0.16 to 2.0.17

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

AI SEO/GEO Analyzer

Moderately critical · 1,027 sites report using it · SA-CONTRIB-2026-076 · on drupal.org

This module creates search engine optimisation reports by sending website content to an artificial intelligence tool.

An ordinary account on the site could trick the artificial intelligence into returning malicious code. This code would run when a user with higher access rights views the report. The attacker could read some restricted data and change or add some data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if an attacker can add text to the content sent to the artificial intelligence tool.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate AI SEO/GEO Analyzer to 1.1.3.

For developers: what the fix changed

The fix introduces a convertMarkdownToSafeHtml method in src/AiSeoAnalyzer.php to strip unsafe HTML and links during Markdown conversion, and applies Xss::filterAdmin to the result. It also updates src/ReportService.php to pass stored report HTML through Xss::filterAdmin before rendering, and updates src/Controller/StreamAnalysisController.php to use the new sanitisation method.

1.1.2 to 1.1.3 2 commits, 3 files.

  • src/AiSeoAnalyzer.php +31 −3 fix
  • src/Controller/StreamAnalysisController.php +2 −3 fix
  • src/ReportService.php +14 −6 fix

Full diff, 1.1.2 to 1.1.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Siteimprove Analytics

Moderately critical · 686 sites report using it · SA-CONTRIB-2026-073 · on drupal.org

This module adds tracking code to every page so the site can be monitored by an analytics service.

The module does not properly clean the analytics identification code. An administrator account could exploit this to read some restricted data and change or add some data.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youThis applies if an attacker has the access right to manage the analytics settings.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Siteimprove Analytics to 2.0.1.

For developers: what the fix changed

The fix escapes the Siteimprove Analytics code configuration value using Html::escape in the siteimprove_analytics_page_attachments function within siteimprove_analytics.module to prevent cross site scripting.

Also in this release Updates to the README.md file.

2.0.0 to 2.0.1 2 commits, 2 files.

  • README.md +5 −5
  • siteimprove_analytics.module +3 −1 fix

Full diff, 2.0.0 to 2.0.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Login Disable

Moderately critical · 499 sites report using it · SA-CONTRIB-2026-070 · on drupal.org

This module prevents users from logging in unless they know a secret key to add to the login page address.

The module does not stop attackers from repeatedly guessing the secret key. An ordinary account on the site could guess the key to bypass the login block. They could then read some restricted data and change or add some data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if an attacker has a valid username and password.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Login Disable to 2.1.4.

For developers: what the fix changed

In login_disable.module, the _login_disable_form_user_login_alter function was updated to integrate flood control, registering failed attempts and blocking access when the limit is reached.

Also in this release Added a GitLab CI test variable and updated the README file.

2.1.3 to 2.1.4 2 commits, 3 files.

  • .gitlab-ci.yml +2 −0
  • README.txt +6 −0
  • login_disable.module +30 −8 fix

Full diff, 2.1.3 to 2.1.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Ray Enterprise Translation

Moderately critical · 156 sites report using it · SA-CONTRIB-2026-071 · on drupal.org

This module helps administrators manage multiple languages on a website.

The module does not protect several administrative pages against forged requests. Anyone without logging in could trick a privileged user into visiting a crafted page that changes translation settings or uploads new translations. They could not read any restricted data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Ray Enterprise Translation to 4.1.4, 11.0.4 or 4.0.4, whichever branch you are on.

For developers: what the fix changed

Adds the `_csrf_token` requirement to multiple administrative routes in `lingotek.routing.yml` and implements manual CSRF token validation for POST and DELETE requests in `LingotekDashboardController::endpoint`.

Also in this release Added basic authentication for Lingotek notification callbacks.

4.1.3 to 4.1.4 1 commit, 16 files.

  • config/schema/lingotek.schema.yml +8 −0
  • lingotek.routing.yml +16 −1 fix
  • lingotek.services.yml +3 −0
  • src/Access/LingotekNotifyAccessCheck.php +147 −0
  • src/Controller/LingotekControllerBase.php +33 −0
  • src/Controller/LingotekDashboardController.php +10 −0 fix
  • src/Controller/LingotekNotificationController.php +0 −4
  • src/Controller/LingotekSetupController.php +5 −1
  • src/Form/LingotekAccountDisconnectForm.php +2 −0
  • src/Form/LingotekConfigFormBase.php +34 −0
  • src/Form/LingotekSettingsDefaultsForm.php +5 −1
  • src/Form/LingotekSettingsTabUtilitiesForm.php +16 −7

Full diff, 4.1.3 to 4.1.4 · Full diff, 11.0.3 to 11.0.4 · Full diff, 4.0.3 to 4.0.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Less critical: 1 update

Fix with the next routine update.

ECA: Event - Condition - Action

Less critical · 21,467 sites report using it · SA-CONTRIB-2026-074 · on drupal.org

This module provides a visual tool to automate tasks on a website without writing code.

The module does not properly clean template code when displaying it. An ordinary account on the site could use this to read some restricted data. They could not change any data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if the site runs an automation model that uses the template rendering action on a data flow.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this less critical. Fix it with the next routine update.

Tell your developerUpdate ECA: Event - Condition - Action to 2.1.20, 3.0.12 or 3.1.4, whichever branch you are on.

For developers: what the fix changed

The fix removes token replacement from the Twig template source in `Drupal\eca_render\Plugin\Action\Twig::doBuild` and its configuration form. This prevents token values from being evaluated as Twig code, closing the server side template injection vulnerability.

Also in this release Refactored a while loop in GetFieldValue and fixed a PHPStan issue in TokenDecoratorTrait.

2.1.19 to 2.1.20 3 commits, 4 files including 1 test.

  • modules/content/src/Plugin/Action/GetFieldValue.php +5 −1
  • modules/render/src/Plugin/Action/Twig.php +2 −3 fix
  • src/Token/TokenDecoratorTrait.php +1 −3

Full diff, 2.1.19 to 2.1.20 · Full diff, 3.0.11 to 3.0.12 · Full diff, 3.1.3 to 3.1.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.