Highly critical · 222 sites report using it · SA-CONTRIB-2026-192 · on drupal.org
It provides the ability to load blocks of content asynchronously without reloading the page.
A visitor could send malicious data to the website to run dangerous code on the server. This could give them total control over the system. They could read or change absolutely everything on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it has the layout builder enabled or uses another block plugin that handles data in an unsafe way.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this highly critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Block AJAX to 3.0.2.
For developers: what the fix changed
The fix modifies src/Controller/AjaxBlockController.php to retrieve block configuration directly from the stored block entity instead of accepting user supplied configuration and plugin IDs from the request. It also updates js/ajax_blocks.js to stop sending these parameters in the AJAX request.
Also in this release The release adds support for cacheable responses and includes various JavaScript and CSS code style updates.
3.0.1 to 3.0.2 5 commits, 11 files.
.cspell-project-words.txt +3 −0
README.md +30 −0
block_ajax.routing.yml +0 −1
css/ajax_blocks.css +10 −8
js/ajax_blocks.js +81 −46 fix
src/AjaxBlocks.php +1 −1
src/BlockViewBuilder.php +1 −1
src/Controller/AjaxBlockController.php +87 −100 fix
src/Controller/AjaxBlockListController.php +1 −1
src/Form/AjaxBlockForm.php +2 −0
src/Response/AjaxBlockResponse.php +2 −3
Full diff, 3.0.1 to 3.0.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · 8,240 sites report using it · SA-CONTRIB-2026-195 · on drupal.org
It integrates a mathematical rendering library into a website.
A user could hide malicious scripts inside math formulas. These scripts could run in the web browser of anyone reading the page. This could let someone read or alter hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate MathJax: LaTeX for Drupal to 4.1.2.
For developers: what the fix changed
The fix updates the default configuration in config/install/mathjax.settings.yml and the library definition in mathjax.module to include the Safe mode parameter in the content delivery network URL. It also adds a requirements check and an update hook in mathjax.install to warn administrators and update existing configurations.
Also in this release The release updates an insecure content delivery network version warning in mathjax.install.
4.1.1 to 4.1.2 1 commit, 3 files.
config/install/mathjax.settings.yml +1 −1 fix
mathjax.install +56 −8 fix
mathjax.module +1 −1 fix
Full diff, 4.1.1 to 4.1.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · 332 sites report using it · SA-CONTRIB-2026-193 · on drupal.org
This module has been withdrawn because of an unfixed security problem.
The Drupal security team has withdrawn the module because of a security problem the maintainer did not fix. The details are not published and it should be treated as unsafe to keep.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.
Tell your developerRemove or replace ECA Helper. There is no fixed version.
For developers: what the fix changed
The module has been withdrawn, so there is no fixed release to compare.
Critical · 261 sites report using it · SA-CONTRIB-2026-196 · on drupal.org
This module has been withdrawn because of an unfixed security problem.
The Drupal security team has withdrawn the module because of a security problem the maintainer did not fix. The details are not published and it should be treated as unsafe to keep.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentThe Drupal security team has withdrawn this module because its maintainer did not fix a known problem. The only remedy is to remove or replace it.
Tell your developerRemove or replace Orphans Media. There is no fixed version.
For developers: what the fix changed
The module has been withdrawn, so there is no fixed release to compare.
Critical · 213 sites report using it · SA-CONTRIB-2026-216 · on drupal.org
It provides an interface to manage page restriction by IP address.
The website fails to block access based on internet addresses for certain dynamic web pages. A visitor could see hidden pages and make changes to them.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it uses this module and has any dynamic pages.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Restrict route by IP to 2.0.1 or 1.3.1, whichever branch you are on.
For developers: what the fix changed
The fix passes the current route collection to the service method fetching restricted routes and alters the route subscriber priority to ensure dynamic routes are properly processed.
Also in this release The release bumps core version requirements, improves type hinting, fixes an issue adding new configuration entities and filters HTML tags from IP and parameter fields.
2.0.0 to 2.0.1 6 commits, 10 files including 1 test.
composer.json +1 −1
restrict_route_by_ip.info.yml +1 −1
src/Controller/RestrictRouteListBuilder.php +11 −2
src/Entity/RestrictRouteByIp.php +50 −5
src/Entity/RestrictRouteInterface.php +6 −7
src/Form/RestrictRouteForm.php +0 −14
src/Routing/RouteSubscriber.php +11 −1 fix
src/Service/RestrictIpInterface.php +11 −3 fix
src/Service/RestrictIpService.php +19 −11
Full diff, 2.0.0 to 2.0.1 · Full diff, 1.3.0 to 1.3.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · 4 sites report using it · SA-CONTRIB-2026-194 · on drupal.org
It allows administrators to identify, analyse, and replace references to pieces of content across the system.
A regular visitor who can view pages could use the merging tool to delete content. They could destroy web pages, media files, or categories. They could also read and alter some restricted details.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Entity Reference Manager (Merge entities) to 1.0.3.
For developers: what the fix changed
The fix adds permission checks to the routing configuration in entity_reference_manager.routing.yml and enforces strict access validation in the execute method of src/Service/ContentMergeManager.php. It also marks the administration permission as restricted in entity_reference_manager.permissions.yml.
1.0.2 to 1.0.3 1 commit, 4 files.
entity_reference_manager.permissions.yml +1 −0 fix
entity_reference_manager.routing.yml +3 −0 fix
entity_reference_manager.services.yml +1 −0 fix
src/Service/ContentMergeManager.php +20 −0 fix
Full diff, 1.0.2 to 1.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · no install count published · SA-CONTRIB-2026-198 · on drupal.org
It collects web activity from external services into native pieces of content for each user.
A visitor could alter settings for other user accounts on the website. They could read hidden configuration details and make unwanted changes to them.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Actstream to 2.1.1 or 2.0.1, whichever branch you are on.
For developers: what the fix changed
The fix updates the routing configuration file to require user update access rather than the generic access content permission for the accounts form route.
Also in this release The release also refactors hashtag filtering in the feed search module and updates class imports for the SimplePie library.
2.1.0 to 2.1.1 2 commits, 30 files including 6 tests.
.cspell.json +17 −1
README.md +1 −1
actstream.api.php +2 −4
actstream.routing.yml +1 −1 fix
actstream_event/src/Entity/ActstreamEventInterface.php +1 −0
actstream_facebook_page/src/Form/SettingsForm.php +1 −1
actstream_feed/src/Hook/ActstreamFeedHooks.php +4 −2
actstream_feed_search/composer.json +11 −0
actstream_feed_search/src/Hook/ActstreamFeedSearchHooks.php +42 −14
actstream_flickr/src/Hook/ActstreamFlickrHooks.php +2 −1
actstream_instagram_search/src/Form/SettingsForm.php +1 −1
actstream_mod_queue/src/Form/ModerationQueueForm.php +4 −4
Full diff, 2.1.0 to 2.1.1 · Full diff, 2.0.0 to 2.0.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · no install count published · SA-CONTRIB-2026-197 · on drupal.org
It provides two factor verification for the login process.
A person with a valid password reset link could access an account without passing the second security step. They could skip the extra security check entirely. This could allow them to see and change restricted data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker has access to a valid one time login link for a victim.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Authenticator Login Plus (2FA) to 1.0.1.
For developers: what the fix changed
The fix updates src/Form/LoginChallengeForm.php and src/Controller/ResetRequestController.php to properly enforce two factor authentication for users logging in via a one time login link. It ensures these users are correctly redirected to the password reset page after verification.
1.0.0 to 1.0.1 1 commit, 9 files.
README.md +11 −8
auth_login_plus.services.yml +2 −0 fix
src/Controller/ResetRequestController.php +6 −0 fix
src/Controller/RestLoginController.php +17 −0 fix
src/EventSubscriber/LoginEnforcementSubscriber.php +4 −2 fix
src/Form/LoginChallengeForm.php +9 −2 fix
src/Form/UserEnrollForm.php +49 −3 fix
src/Hook/AuthLoginPlusHooks.php +25 −0
src/Service/LoginChallengeManager.php +138 −8
Full diff, 1.0.0 to 1.0.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 106,436 sites report using it · SA-CONTRIB-2026-212 · on drupal.org
It shows a trail of links for category hierarchies on a page.
A visitor could see the names of unpublished parent categories in the website trail. They could read these hidden names. They could not open those pages or change anything.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the add parent hierarchy setting is enabled and at least one category has an unpublished parent category.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Easy Breadcrumb to 2.0.11.
For developers: what the fix changed
The fix introduces a view access check, $parent->access('view'), for parent taxonomy terms in the build method of src/EasyBreadcrumbBuilder.php, so users cannot see breadcrumb segments for unpublished or otherwise restricted terms.
Also in this release Other changes include cache context and tag updates, HTML tag stripping for breadcrumb items, fixes for admin route exclusions, and test implementations.
2.0.10 to 2.0.11 6 commits, 17 files including 9 tests.
composer.json +2 −0
easy_breadcrumb.module +35 −1
easy_breadcrumb.services.yml +6 −1
src/Cache/EasyBreadcrumbCacheContext.php +74 −0
src/EasyBreadcrumbBuilder.php +81 −69 fix
src/EasyBreadcrumbStructuredDataJsonLd.php +4 −12
src/Form/EasyBreadcrumbGeneralSettingsForm.php +1 −3
src/TitleResolver.php +7 −14
Full diff, 2.0.10 to 2.0.11
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 91,515 sites report using it · SA-CONTRIB-2026-209 · on drupal.org
It allows administrators to add extra details to menu links and their container elements.
An administrator could add unsafe text to website menus. This text could run malicious scripts when other people visit the page. This could let someone read or change private data.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youA site is affected if an attacker has access rights to administer menus and use menu link attributes, and an unsafe container attribute is already configured.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Menu Link Attributes to 8.x-1.8.
For developers: what the fix changed
The fix introduces the menu_link_attributes_is_allowed_attribute_name and menu_link_attributes_filter_attributes functions in menu_link_attributes.module to validate and sanitise configuration. It applies these checks in the validateForm method of ConfigForm.php and includes an update hook in menu_link_attributes.install to strip unsafe attributes.
Also in this release The release also updates configuration descriptions and adds functional tests for the new validation.
8.x-1.7 to 8.x-1.8 2 commits, 5 files including 1 test.
config/install/menu_link_attributes.config.yml +2 −2
menu_link_attributes.install +28 −0 fix
menu_link_attributes.module +78 −2 fix
src/Form/ConfigForm.php +14 −1 fix
Full diff, 8.x-1.7 to 8.x-1.8
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 30,905 sites report using it · SA-CONTRIB-2026-204 · on drupal.org
It provides integration with a specific mapping library to display maps.
A content editor could place malicious scripts in map titles. These scripts could run in the web browser of anyone viewing the map. This could allow someone to see or change restricted data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to create or edit content that is used in a map.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Leaflet to 10.4.13.
For developers: what the fix changed
Removes entity decoding of tooltip values in the LeafletMap style plugin and updates the JavaScript alternative text extraction to use DOMParser instead of a regular expression to prevent cross site scripting.
Also in this release Adds configuration schema settings for popup and marker clustering options, updates JavaScript to preserve original features implementation, and removes underline tags from user interface strings.
10.4.12 to 10.4.13 5 commits, 8 files.
config/schema/leaflet.schema.yml +12 −0
css/leaflet_general.css +3 −3
js/leaflet.drupal.js +1 −1 fix
modules/leaflet_markercluster/leaflet_markercluster.drupal.js +18 −0
modules/leaflet_views/src/Plugin/views/style/LeafletMap.php +2 −4 fix
sass/leaflet_general.scss +3 −3
src/LeafletSettingsElementsTrait.php +11 −11
src/Plugin/Field/FieldFormatter/LeafletDefaultFormatter.php +42 −12
Full diff, 10.4.12 to 10.4.13
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 13,136 sites report using it · SA-CONTRIB-2026-200 · on drupal.org
It enables administrators to link the output of a field to a URL or to the value of another field.
A content editor could add malicious code into specific fields. This code could reveal secret website settings like passwords or system keys. This could let someone read or alter restricted data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to create or edit content in a field that has this module enabled in its display settings.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Linked Field to 8.x-1.8.
For developers: what the fix changed
The fix alters the entity display build hook in the main module file to output the linked HTML as plain markup rather than an inline template. This ensures that user provided field content is not evaluated as Twig code.
Also in this release The release also adds validation for the configuration form, stringifies class attributes, and updates continuous integration testing variables.
8.x-1.7 to 8.x-1.8 7 commits, 10 files including 4 tests.
.gitlab-ci.yml +7 −4
README.md +36 −9
composer.json +8 −0
linked_field.module +20 −7 fix
src/Form/ConfigForm.php +23 −1
src/LinkedFieldManager.php +4 −0
Full diff, 8.x-1.7 to 8.x-1.8
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 6,359 sites report using it · SA-CONTRIB-2026-214 · on drupal.org
It restricts view access to single pieces of content using categories.
A visitor could view restricted content through data feeds if it was linked to a deleted category. They could read this hidden information. They could not alter or add any data on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it uses permission mode, has references to a deleted category, and is accessed via a data feed.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Permissions by Term to 3.1.41.
For developers: what the fix changed
The fix updates the node access hook to return an explicit access result object and modifies the access check service to return neutral or forbidden access results instead of void.
Also in this release The release updates the Axios library to a secure version, fixes typos in comments and configures ignore paths for the spell checker.
3.1.40 to 3.1.41 3 commits, 13 files.
.gitlab-ci.yml +2 −0
js/README.md +5 −5
js/package-lock.json +5 −4
js/package.json +1 −1
js/webpack-dist/bundle.js +0 −0
js/webpack-dist/bundle.js.LICENSE.txt +1 −1
permissions_by_term.install +2 −2
permissions_by_term.module +2 −2 fix
src/Commands/CreateFixtureNodesForTestingCommands.php +1 −1
src/Commands/PermissionsByTermRebuildCommands.php +1 −1
src/Listener/KernelEventListener.php +1 −1
src/Service/AccessCheck.php +5 −3 fix
Full diff, 3.1.40 to 3.1.41
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 5,103 sites report using it · SA-CONTRIB-2026-202 · on drupal.org
It provides a new interface for editing pieces of content using a block editor.
A writer using the visual editor could access restricted parts of the system. They could read hidden information through the editor tools. They could also alter some restricted content.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has a role with the use gutenberg access right.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Gutenberg to 8.x-2.15 or 3.0.7, whichever branch you are on.
For developers: what the fix changed
Adds missing entity access checks by adding _entity_access requirements to several routes in gutenberg.routing.yml and explicitly verifying view access in src/Controller/MediaController.php and src/Service/MediaService.php.
Also in this release Normalised configuration schemas, added the missing core block, and improved UI logic for moving fields and selecting blocks.
8.x-2.14 to 8.x-2.15 6 commits, 19 files.
config/install/gutenberg.mediaedit.yml +0 −1
config/schema/gutenberg.schema.yml +3 −1
gutenberg.api.php +28 −0
gutenberg.blocks.yml +3 −2
gutenberg.install +5 −2
gutenberg.module +212 −94
gutenberg.post_update.php +61 −0
gutenberg.routing.yml +11 −1 fix
js/admin.es6.js +15 −3
js/admin.js +10 −3
js/drupal-blocks.js +1 −1
js/drupal-media.es6.js +1 −1
Full diff, 8.x-2.14 to 8.x-2.15 · Full diff, 3.0.6 to 3.0.7
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 4,458 sites report using it · SA-CONTRIB-2026-211 · on drupal.org
It provides a dedicated field for the official country list of the system.
An administrator could store malicious scripts in the country text box. These scripts could run when other people use the website. This could let someone read or change private data.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youA site is affected if additional modules or custom code are used alongside it.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Country to 2.1.3 or 2.2.1, whichever branch you are on.
For developers: what the fix changed
The fix escapes the country label using the HTML utility class before returning it in the autocomplete widget matches within the country autocomplete controller.
2.1.2 to 2.1.3 1 commit, 1 file.
src/Controller/CountryAutocompleteController.php +4 −1 fix
Full diff, 2.1.2 to 2.1.3 · Full diff, 2.2.0 to 2.2.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 651 sites report using it · SA-CONTRIB-2026-207 · on drupal.org
It adds an extra layer of verification for the user login process.
A visitor could see the secret customer key used for the background login service. They could read this hidden text. They could not alter the website or add new information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the headless verification setting is turned on by a user with a restricted access right.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Two Factor Authentication - TFA / Passwordless Login to 5.4.1 or 5.5.2, whichever branch you are on.
For developers: what the fix changed
The fix implements the moHeadlessApiKeyIsValid and moHeadlessRejectApiKey methods in miniorange_2faController.php to perform a constant time API key comparison without returning the key in the response. It also introduces a dedicated backdoor token generated by hooks in miniorange_2fa.install to further separate secrets.
Also in this release The release also updates module version metadata and restricts the headless routes to accept only post requests.
5.4.0 to 5.4.1 1 commit, 9 files.
config/schema/miniorange_2fa.schema.yml +4 −1 fix
miniorange_2fa.info.yml +7 −2
miniorange_2fa.install +22 −1 fix
miniorange_2fa.routing.yml +10 −2 fix
modules/miniorange_webauthn/miniorange_webauthn.info.yml +6 −1
src/Controller/miniorange_2faController.php +139 −44 fix
src/Form/MoAuthHeadlessSetup.php +3 −3
src/Form/MoAuthLoginSettings.php +6 −2
src/MoAuthUtilities.php +44 −3
Full diff, 5.4.0 to 5.4.1 · Full diff, 5.5.1 to 5.5.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 641 sites report using it · SA-CONTRIB-2026-206 · on drupal.org
It generates detailed technical reports about the content and configuration of a website.
A visitor could view unpublished content through a specific preview page. They could read hidden draft pages but not restricted details like user email addresses. They could not change or add anything on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Xray Audit to 2.0.4, 3.1.1 or 1.6.3, whichever branch you are on.
For developers: what the fix changed
The fix updates xray_audit.routing.yml to require the xray_audit access permission and enforce entity view access for the example route. It also modifies XrayAuditDisplayModeExampleController.php to upcast the entity parameter in the displayEntity method and verify view access before selecting candidate entities.
Also in this release The release includes an array key check in a preprocess hook to prevent errors and adds a test class.
2.0.3 to 2.0.4 1 commit, 4 files including 1 test.
src/Controller/XrayAuditDisplayModeExampleController.php +38 −19 fix
xray_audit.module +7 −3
xray_audit.routing.yml +6 −5 fix
Full diff, 2.0.3 to 2.0.4 · Full diff, 3.1.0 to 3.1.1 · Full diff, 1.6.2 to 1.6.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 220 sites report using it · SA-CONTRIB-2026-213 · on drupal.org
It provides a filter framework for easier creation of links to other pages on a site or to external sites.
A user with the right access could see the titles of private web links. They could read this hidden text. They could not change or delete anything.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to use a text format configured to allow private external URLs to be crawled.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Freelinking to 4.0.3.
For developers: what the fix changed
The fix introduces a method in the External plugin to verify whether an external URL should be crawled, ensuring that private IP ranges are not accessed to retrieve page titles. It also changes the default setting to disable scraping and updates the configuration description to warn about potential exposure.
Also in this release The release includes updates to PHPStan configuration paths and adds a new unit test for external host URL checking.
4.0.2 to 4.0.3 1 commit, 3 files including 1 test.
phpstan.neon.dist +4 −4
src/Plugin/freelinking/External.php +28 −5 fix
Full diff, 4.0.2 to 4.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 170 sites report using it · SA-CONTRIB-2026-203 · on drupal.org
It allows site builders to use templates and style pieces of content with a field.
A user could place malicious commands in a text field. These commands could expose secret system data or run unsafe code on the server. This could let someone read or alter hidden information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Inline Formatter Field to 4.2.0.
For developers: what the fix changed
Escapes curly braces in token replacements by converting them to HTML entities in the inline formatter display module and field formatter plugin, and refactors token fetching in the Views field plugin to prevent server side template injection.
Also in this release Adds the inline formatter field as an enforced dependency to the Ace Editor text format.
4.1.0 to 4.2.0 3 commits, 5 files.
config/install/filter.format.iff_ace_editor.yml +4 −1
inline_formatter_field.install +22 −0
modules/inline_formatter_display/inline_formatter_display.module +12 −1 fix
modules/inline_formatter_views_field/src/Plugin/views/field/InlineFormatterViewsField.php +5 −21 fix
src/Plugin/Field/FieldFormatter/InlineFormatterFieldFormatter.php +16 −1 fix
Full diff, 4.1.0 to 4.2.0
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 146 sites report using it · SA-CONTRIB-2026-208 · on drupal.org
It enables organisations to build open data portals to import and share tabular data.
A visitor could read imported data tables through data feeds. They could see this hidden information even if the website restricts general access. They could not change or delete any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it does not give the access content access right to visitors without an account.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate DKAN to 4.1.5 or 4.0.4, whichever branch you are on.
For developers: what the fix changed
The fix updates dkan_datastore.routing.yml to replace the generic access requirement with the access content permission requirement for the dkan_datastore.sql_endpoint.post.api route.
4.1.4 to 4.1.5 1 commit, 1 file.
modules/dkan_datastore/dkan_datastore.routing.yml +1 −1 fix
Full diff, 4.1.4 to 4.1.5 · Full diff, 4.0.3 to 4.0.4
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 25 sites report using it · SA-CONTRIB-2026-205 · on drupal.org
It enables administrators to share a view of content within another website.
A visitor could trigger heavy database searches by guessing hidden web addresses. They could slow down the website. They could not see any hidden data or alter any website content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker knows the specific IDs of the view and display.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Views Share to 2.0.1.
For developers: what the fix changed
Adds an access check for the display ID to the view object in the preview, oembed, and modal methods of the ViewsShareController class.
Also in this release Updates the oembed method return type and changes how the format parameter is retrieved to resolve PHPStan issues.
2.0.0 to 2.0.1 1 commit, 1 file.
src/Controller/ViewsShareController.php +5 −5 fix
Full diff, 2.0.0 to 2.0.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 15 sites report using it · SA-CONTRIB-2026-210 · on drupal.org
It automates internal linking to improve search engine visibility, user experience and editor efficiency.
A content writer could see search results for restricted pages when generating internal links. They could read the names of hidden pages. They could not alter these pages.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if a user has an access right to use the generate internal links feature on a text format.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate SmartLinker AI to 1.0.3.
For developers: what the fix changed
The fix removes the search option that bypassed access checks and adds an explicit view access check for the node entity before returning its canonical URL in the SmartLinkerAI plugin.
Also in this release The release fixes a fatal error related to generating internal links without a parent subrequest and updates the spell check configuration.
1.0.1 to 1.0.3 3 commits, 2 files.
.cspell.json +2 −1
src/Plugin/AiCKEditor/SmartLinkerAI.php +1 −6 fix
Full diff, 1.0.1 to 1.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 13 sites report using it · SA-CONTRIB-2026-199 · on drupal.org
It renders forms for pieces of content inside a pop up window instead of placing them directly on the page.
A user who can view administrative pages could alter content they do not normally control. They could read restricted details and change information inside popup forms.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to access administration pages.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Inline Entity Form Dialog to 1.0.6.
For developers: what the fix changed
The fix introduces explicit entity create and update access checks inside the add and edit methods of the dialog controller. This ensures users cannot bypass entity level permissions when using the dialog widget.
Also in this release Bundle labels now have HTML tags stripped before output and a boolean cast was added to a widget setting to prevent type errors.
1.0.5 to 1.0.6 4 commits, 2 files.
src/Controller/InlineEntityFormDialogController.php +15 −0 fix
src/Plugin/Field/FieldWidget/InlineEntityFormDialogWidget.php +7 −7
Full diff, 1.0.5 to 1.0.6
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · no install count published · SA-CONTRIB-2026-217 · on drupal.org
It turns the file storage of a website into a manageable and observable system.
A malicious website could trick a logged in visitor into making unwanted changes. Someone could trigger a system backup or alter some data. They could not see any hidden information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the advanced filesystem backup feature is enabled.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Advanced Filesystem to 1.0.28.
For developers: what the fix changed
The fix adds a CSRF token requirement to multiple administrative route definitions within the advanced filesystem backup routing configuration.
1.0.27 to 1.0.28 1 commit, 1 file.
modules/advanced_filesystem_backup/advanced_filesystem_backup.routing.yml +6 −0 fix
Full diff, 1.0.27 to 1.0.28
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · no install count published · SA-CONTRIB-2026-201 · on drupal.org
It provides two factor verification with an optional setting to enforce it for all users.
A user could log in using only a password even when a second security step is required. They could access their account without the extra security check. Once logged in they could see and change data normally available to their account.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if site wide enforcement is turned on.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Authenticator Login Plus (2FA) to 1.0.1.
For developers: what the fix changed
The fix modifies the login enforcement subscriber to check if two factor authentication is enabled rather than merely existing. It also updates the user enrol form to force re enrolment if a user has disabled their two factor authentication.
Also in this release REST login endpoints and reset request controllers were updated to handle edge cases and block invalid sessions.
1.0.0 to 1.0.1 1 commit, 9 files.
README.md +11 −8
auth_login_plus.services.yml +2 −0
src/Controller/ResetRequestController.php +6 −0
src/Controller/RestLoginController.php +17 −0
src/EventSubscriber/LoginEnforcementSubscriber.php +4 −2 fix
src/Form/LoginChallengeForm.php +9 −2
src/Form/UserEnrollForm.php +49 −3 fix
src/Hook/AuthLoginPlusHooks.php +25 −0
src/Service/LoginChallengeManager.php +138 −8
Full diff, 1.0.0 to 1.0.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Less critical · 797 sites report using it · SA-CONTRIB-2026-215 · on drupal.org
It provides documented code examples for a broad range of website functions.
A visitor could use the email example feature to send unwanted messages to any address. They could not see any hidden data or change website content. The development team is removing this feature.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if it uses the email example feature.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate Examples for Developers to 4.0.7.
For developers: what the fix changed
The fix completely removes the vulnerable email example module and all its associated files from the codebase.
4.0.6 to 4.0.7 1 commit, 6 files including 1 test.
modules/email_example/email_example.info.yml +0 −8 fix
modules/email_example/email_example.links.menu.yml +0 −4 fix
modules/email_example/email_example.module +0 −99 fix
modules/email_example/email_example.routing.yml +0 −6 fix
modules/email_example/src/Form/EmailExampleGetFormPage.php +0 −163 fix
Full diff, 4.0.6 to 4.0.7
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.