Critical · 4,321 sites report using it · SA-CONTRIB-2026-132 · on drupal.org
This module creates access rights per content type to control who can see unpublished pieces of content.
The module allows people to see published pieces of content even if other access rules should hide them. A visitor could read published content that should be hidden. They could not change any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Unpublished Node Permissions to 8.x-1.8.
For developers: what the fix changed
The fix removes the code in unpublished_node_permissions_node_access_records within unpublished_node_permissions.module that incorrectly granted view access to published content. It also adds an update hook in unpublished_node_permissions.install to rebuild node access.
8.x-1.7 to 8.x-1.8 1 commit, 2 files.
unpublished_node_permissions.install +7 −0 fix
unpublished_node_permissions.module +0 −10 fix
Full diff, 8.x-1.7 to 8.x-1.8
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · 820 sites report using it · SA-CONTRIB-2026-127 · on drupal.org
This module restricts access to data feeds based on specific user roles.
The module does not properly enforce access rules when a request mimics a specific type of background web request. A visitor could read hidden data feeds or change data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Jsonapi Role Access to 2.0.2.
For developers: what the fix changed
The fix removes the `isXmlHttpRequest()` check from the early return condition in `checkUserRoleAccess` within `src/EventSubscriber/CheckUserRolePermissionEvent.php`, ensuring that requests mimicking XMLHttpRequests cannot bypass role access restrictions.
Also in this release Added a functional test to verify that XMLHttpRequest headers cannot bypass role restrictions.
2.0.1 to 2.0.2 1 commit, 2 files including 1 test.
src/EventSubscriber/CheckUserRolePermissionEvent.php +6 −5 fix
Full diff, 2.0.1 to 2.0.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · 48 sites report using it · 2 security fixes
This module adds an extra layer of verification for user registration.
2 security fixes in one update. Email Verification / SMS Verification / OTP Verification fixed 2 separate security bugs this week: 1 cross site scripting, 1 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-125, is explained here and the full list is at the end of the card.
The module does not properly filter user supplied text before displaying it. A visitor could read hidden data or change data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Email Verification / SMS Verification / OTP Verification to 8.x-2.4.
For developers: what the fix changed
This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-125, the most serious of them.
The fix removes the insecure passing of error messages via the `q` URL parameter and its subsequent unescaped output in `otp_verification_form_user_register_form_alter` within `otp_verification.module`. It also updates message rendering in `src/Form/MiniorangeValidateUser.php` to use proper placeholders like `@msg` in the `t()` function and escapes the `tx_id` parameter to prevent XSS.
Also in this release The release also includes bug fixes related to session handling, cookie management, and redirect logic.
8.x-2.3 to 8.x-2.4 1 commit, 4 files.
otp_verification.module +66 −47 fix
src/Form/MiniorangeValidateUser.php +107 −56 fix
src/MiniorangeOtpUtilities.php +19 −4
src/Plugin/OtpValidation/OtpValidator.php +18 −2
Full diff, 8.x-2.3 to 8.x-2.4
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.
Critical · 26 sites report using it · SA-CONTRIB-2026-122 · on drupal.org
This module calculates working days between two dates.
The module does not properly restrict access to its settings page. A visitor could change the module settings. They could not read any hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Calculate Working Days to 2.0.3.
For developers: what the fix changed
The fix updates the routing configuration in calculate_working_days.routing.yml to require the administer site configuration permission instead of access content.
2.0.2 to 2.0.3 1 commit, 1 file.
calculate_working_days.routing.yml +1 −1 fix
Full diff, 2.0.2 to 2.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 23,475 sites report using it · 2 security fixes
This module automatically translates pieces of content.
2 security fixes in one update. AI (Artificial Intelligence) fixed 2 separate security bugs this week: 1 access bypass, 1 cross site scripting. One update covers all of them. The most serious, SA-CONTRIB-2026-120, is explained here and the full list is at the end of the card.
The module does not properly check access rights on related fields or referenced items during translation. A user with an ordinary account could translate items they should not have access to. They could not read or update the affected items in other ways.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AI (Artificial Intelligence) to 1.3.13 or 1.4.8, whichever branch you are on.
For developers: what the fix changed
This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-120, the most serious of them.
This fix adds a custom access callback named `checkAccess` in `AiTranslateController.php` to verify entity update and translation access. It also introduces field and referenced entity access checks in `TextExtractor.php` and `ReferenceFieldExtractor.php` to ensure users can only translate content they are permitted to view and update.
Also in this release The release also fixes a cross site scripting vulnerability in the AI Chatbot module by filtering YAML output and updates package versions.
1.3.12 to 1.3.13 5 commits, 10 files.
modules/ai_chatbot/src/Controller/DeepChatApi.php +1 −1
modules/ai_chatbot/src/Form/ChatForm.php +3 −3
modules/ai_ckeditor/package-lock.json +2 −2
modules/ai_ckeditor/package.json +1 −1
modules/ai_translate/ai_translate.routing.yml +2 −1 fix
modules/ai_translate/src/Controller/AiTranslateController.php +61 −1 fix
modules/ai_translate/src/Plugin/FieldTextExtractor/ReferenceFieldExtractor.php +2 −2 fix
modules/ai_translate/src/TextExtractor.php +4 −0 fix
ui/mdxeditor/package-lock.json +2 −2
ui/mdxeditor/package.json +1 −1
Full diff, 1.3.12 to 1.3.13 · Full diff, 1.4.7 to 1.4.8
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.
Moderately critical · 18,493 sites report using it · SA-CONTRIB-2026-131 · on drupal.org
This module allows a website to add dynamic captions to image galleries.
The module does not properly clean user supplied text like image descriptions. A user with an ordinary account could read hidden data or change data on the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module where an attacker has an access right that permits them to enter HTML content.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate PhotoSwipe - Responsive JavaScript Modal Image Gallery to 5.0.9.
For developers: what the fix changed
The fix escapes the caption title using Drupal.checkPlain in modules/photoswipe_dynamic_caption/js/photoswipe_dynamic_caption.init.js and removes the previous escaping in modules/photoswipe_dynamic_caption/photoswipe_dynamic_caption.module.
Also in this release The release also improves media translation context handling in src/ImageDTO.php.
5.0.8 to 5.0.9 2 commits, 3 files.
modules/photoswipe_dynamic_caption/js/photoswipe_dynamic_caption.init.js +3 −1 fix
modules/photoswipe_dynamic_caption/photoswipe_dynamic_caption.module +4 −2 fix
src/ImageDTO.php +6 −2
Full diff, 5.0.8 to 5.0.9
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 5,948 sites report using it · SA-CONTRIB-2026-121 · on drupal.org
This module automatically translates pieces of content.
The module does not properly check access rights on related fields or referenced items during translation. A user with an ordinary account could translate items they should not have access to. They could not read or update the affected items in other ways.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AI Translate to 1.3.2 or 1.4.1, whichever branch you are on.
For developers: what the fix changed
The fix replaces the generic permission check on the translation route with a custom access callback in `AiTranslateController::checkAccess` to ensure the user has update access to the entity and translation create access. It also adds field-level view access checks in `TextExtractor` and referenced entity view and update access checks in `ReferenceFieldExtractor`.
Also in this release The release also adds translation result caching, support for translating the 'description' field in custom menu link content, GitLab CI configuration, and documentation.
1.3.1 to 1.3.2 11 commits, 44 files including 8 tests.
.cspell-project-words.txt +11 −0
.gitlab-ci.yml +73 −0
.gitlab/issue_templates/bug_report.md +69 −0
.gitlab/issue_templates/feature_request.md +48 −0
.gitlab/issue_templates/plan.md +75 −0
.gitlab/issue_templates/support_request.md +64 −0
.gitlab/issue_templates/task.md +72 −0
.gitlab/merge_request_templates/Default.md +58 −0
README.md +4 −0
ai_translate.module +9 −37
ai_translate.post_update.php +24 −0
ai_translate.routing.yml +2 −1 fix
Full diff, 1.3.1 to 1.3.2 · Full diff, 1.4.0 to 1.4.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 2,081 sites report using it · SA-CONTRIB-2026-128 · on drupal.org
This module records sent emails as pieces of content so they can be reviewed in a report.
The module does not hide sensitive information in the emails it records. An administrator could see one time login links for any account and use them to log in as that person. They could read hidden data and change data.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youAny site using this module where an attacker has the access right to view the mail log.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Mailer Plus Log to 1.2.7.
For developers: what the fix changed
The fix introduces an email redactor service in `src/EmailRedactor.php` to remove sensitive login links from email bodies. This redaction is applied before saving the log entry in the `preSave` method of `src/Entity/SymfonyMailerLog.php`.
Also in this release Added tests, updated documentation, and added CSpell dictionary words.
1.2.6 to 1.2.7 1 commit, 17 files including 4 tests.
.gitlab-ci.yml +2 −0
README.md +31 −0
src/EmailRedactor.php +138 −0 fix
src/EmailRedactorInterface.php +36 −0 fix
src/Entity/SymfonyMailerLog.php +59 −0 fix
src/Entity/SymfonyMailerLogInterface.php +10 −0 fix
src/Plugin/Field/FieldFormatter/SymfonyMailerLogHtmlBody.php +13 −0 fix
src/RedactionMode.php +21 −0 fix
symfony_mailer_log.api.php +67 −0 fix
symfony_mailer_log.install +16 −0 fix
symfony_mailer_log.permissions.yml +3 −0 fix
symfony_mailer_log.post_update.php +77 −0 fix
Full diff, 1.2.6 to 1.2.7
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 818 sites report using it · SA-CONTRIB-2026-129 · on drupal.org
This module imports media files into a media library.
The module copies files from any folder the web user can read into the public files folder. A user with an ordinary account could make private files available for anyone to download at a predictable web address. They could not change any data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Media Library Importer to 2.1.6.
For developers: what the fix changed
The fix adds validation in `ConfigurationForm::validateForm` and `MediaLibraryImporterService::isWithinPublicFilesDirectory` to ensure that the configured import folder is located within the public files directory, preventing access to arbitrary directories.
Also in this release Added a 'process_queue_on_submit' setting, improved queue processing logic, updated documentation, and fixed PHPStan/PHPCS issues.
2.1.5 to 2.1.6 22 commits, 20 files.
.gitlab-ci.yml +30 −0
Agents.md +69 −0
CLAUDE.md +5 −0
README.md +58 −31
composer.json +1 −1
config/install/media_library_importer.settings.yml +1 −0
config/schema/media_library_importer.schema.yml +4 −0
doc/drupal_org_documentation/description.html +15 −1
media_image_exif_importer/media_image_exif_importer.info.yml +0 −1
media_image_exif_importer/src/Plugin/media/Source/ImageWithExif.php +1 −1
media_library_importer.install +13 −11
media_library_importer.links.menu.yml +12 −12
Full diff, 2.1.5 to 2.1.6
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 726 sites report using it · SA-CONTRIB-2026-126 · on drupal.org
This module provides background updates for advanced search and search result blocks.
The module does not properly check access rights when block IDs are sent to its public address. A visitor could read restricted block content. They could not change any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module where a restricted block contains sensitive content and its ID is known or guessed.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Islandora to 2.19.0.
For developers: what the fix changed
The `islandora_advanced_search` sub-module has been completely removed from the codebase to resolve the access bypass vulnerability.
Also in this release The release also includes a fix for microservice rewrite for canonical event URLs.
2.18.5 to 2.19.0 2 commits, 55 files including 1 test.
modules/islandora_advanced_search/CONTRIBUTING.md +0 −73
modules/islandora_advanced_search/LICENSE +0 −339
modules/islandora_advanced_search/README.md +0 −261
modules/islandora_advanced_search/css/islandora_advanced_search.form.css +0 −37
modules/islandora_advanced_search/css/islandora_advanced_search.pager.css +0 −111
modules/islandora_advanced_search/docs/advanced_search_block_settings.png +0 −0
modules/islandora_advanced_search/docs/basic-input.png +0 −0
modules/islandora_advanced_search/docs/contextual_filter_settings.png +0 −0
modules/islandora_advanced_search/docs/demo.gif +0 −0
modules/islandora_advanced_search/docs/enable_index_hierarchy.png +0 −0
modules/islandora_advanced_search/docs/enable_index_hierarchy_processor.png +0 −0
modules/islandora_advanced_search/docs/exclude_facet_settings_exclude.png +0 −0
Full diff, 2.18.5 to 2.19.0
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 712 sites report using it · SA-CONTRIB-2026-118 · on drupal.org
This module provides background updates for advanced search and search result blocks.
The module does not properly check access rights when block IDs are sent to its public address. A visitor could read restricted block content. They could not change any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module where a restricted block contains sensitive content and its ID is known or guessed.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Advanced Search to 2.4.5.
For developers: what the fix changed
The fix adds an access check for the view operation on the block entity in src/Controller/AjaxBlocksController.php before rendering it.
Also in this release Added a functional test to ensure block access is enforced.
2.4.2 to 2.4.5 1 commit, 2 files including 1 test.
src/Controller/AjaxBlocksController.php +1 −1 fix
Full diff, 2.4.2 to 2.4.5
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 393 sites report using it · SA-CONTRIB-2026-133 · on drupal.org
This module allows a website to delete form submissions in bulk using a specified date range.
The module does not properly restrict access to the delete page. A visitor could delete form submissions. They could not read any hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Webform Submissions Delete to 8.x-1.2.
For developers: what the fix changed
The fix restricts access to the bulk delete form by changing the routing requirement in webform_submissions_delete.routing.yml from access content to webform.submission_purge_any and adds accessCheck(TRUE) to entity queries in src/Form/WebformResultsBulkDeleteForm.php.
Also in this release Added Drupal 11 compatibility and maintainer information.
8.x-1.1 to 8.x-1.2 3 commits, 5 files.
README.md +3 −0
composer.json +6 −1
src/Form/WebformResultsBulkDeleteForm.php +2 −2 fix
webform_submissions_delete.info.yml +1 −1
webform_submissions_delete.routing.yml +1 −1 fix
Full diff, 8.x-1.1 to 8.x-1.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 179 sites report using it · SA-CONTRIB-2026-123 · on drupal.org
This module allows a website to use user interface patterns with blocks in the layout builder.
The module does not properly check user input before replacing text placeholders. A user with an ordinary account could read hidden data or change data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module where an attacker has an access right to edit layouts.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Component blocks to 1.2.7.
For developers: what the fix changed
The fix applies Xss::filterAdmin to the value before token replacement in the ComponentBlock class.
1.2.6 to 1.2.7 1 commit, 2 files including 1 test.
src/Plugin/Block/ComponentBlock.php +2 −1 fix
Full diff, 1.2.6 to 1.2.7
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 48 sites report using it · SA-CONTRIB-2026-130 · on drupal.org
This module connects a website to the Monobank payment service.
The module does not check the digital signature from Monobank before processing payment status updates. A visitor could change payment statuses. They could not read any hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Monobank payment API to 1.0.3.
For developers: what the fix changed
Adds webhook signature verification in the `status` callback within `src/Controller/Pages.php` and implements the verification logic in `src/Monobank.php`.
Also in this release Added Drupal 12 support, dropped Drupal 9, migrated hooks to a new class using attributes, and updated translation method calls.
1.0.2 to 1.0.3 3 commits, 9 files.
monobank.info.yml +2 −2
monobank.module +12 −33
monobank.services.yml +4 −0
src/Controller/Pages.php +22 −15 fix
src/Form/MonobankPaymentsForm.php +9 −9
src/Form/SettingsForm.php +4 −4
src/Hook/MonobankHooks.php +84 −0
src/Monobank.php +115 −3 fix
src/Plugin/Basket/Payment/BasketMonobank.php +5 −5
Full diff, 1.0.2 to 1.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.