🚨 CVE-2026-16647
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
🎖@cveNotify
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
🎖@cveNotify
Drupal.org
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
This module enables you to disable access to the /user/login form unless a secret key is provided. The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may…
🚨 CVE-2026-18986
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.
🎖@cveNotify
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.
🎖@cveNotify
Drupal.org
Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094
The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget. The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability. The vulnerability…
🚨 CVE-2026-73474
Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.
🎖@cveNotify
Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.
🎖@cveNotify
Drupal.org
Entity Share Websub - Moderately critical - Server-side request forgery (SSRF) - SA-CONTRIB-2026-097
This module enables you to share content between sites in a hub - subscriber model. Certain inputs were not sufficiently validated, allowing an attacker to achieve server-side request forgery attacks.
🚨 CVE-2026-73475
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
🎖@cveNotify
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
🎖@cveNotify
Drupal.org
Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
This module enables you to pay for Commerce transactions using Paypal. The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment. This vulnerability only…
🚨 CVE-2026-73476
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
🎖@cveNotify
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
🎖@cveNotify
Drupal.org
External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
This module enables you to authenticate Drupal users against external identity providers. The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database…
🚨 CVE-2026-73477
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
🎖@cveNotify
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
🎖@cveNotify
Drupal.org
Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099
This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance. The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant…
🚨 CVE-2026-73478
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
🎖@cveNotify
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
🎖@cveNotify
Drupal.org
Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
This module enables you to view the differences between revisions on any entity type. The module doesn't sufficiently restrict access to non-node entity revision diffs. This vulnerability is mitigated by the fact that an attacker must have a role with the…
🚨 CVE-2026-76755
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
🎖@cveNotify
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
🎖@cveNotify
Drupal.org
Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that…
🚨 CVE-2026-76756
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
🎖@cveNotify
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
🎖@cveNotify
Drupal.org
Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that…
🚨 CVE-2026-76757
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
🎖@cveNotify
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
🎖@cveNotify
Drupal.org
Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that…
🚨 CVE-2026-76758
Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.
🎖@cveNotify
Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.
🎖@cveNotify
Drupal.org
Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that…
🚨 CVE-2026-76759
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
🎖@cveNotify
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
🎖@cveNotify
Drupal.org
Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that…
🚨 CVE-2026-76782
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
🎖@cveNotify
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
🎖@cveNotify
Drupal.org
Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that…
🚨 CVE-2026-81158
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
🎖@cveNotify
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
🎖@cveNotify
Drupal.org
Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties. The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure…
🚨 CVE-2026-81159
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
🎖@cveNotify
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
🎖@cveNotify
Drupal.org
Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106
This module integrates Drupal Commerce with the CyberSource payment gateway. The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment…
🚨 CVE-2026-81161
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
🎖@cveNotify
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
🎖@cveNotify
Drupal.org
Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted. A site administrator might inadvertently grant this permission to less-trusted users. This would allow those…
🚨 CVE-2026-81162
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
🎖@cveNotify
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
🎖@cveNotify
Drupal.org
DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112
The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata. The 2.x version of the module does not sufficiently restrict access to…
🚨 CVE-2026-81164
Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.
🎖@cveNotify
Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.
🎖@cveNotify
Drupal.org
Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114
The Entity PDF module can create a PDF from any entity based on any View mode. This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.
🚨 CVE-2026-81165
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
🎖@cveNotify
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
🎖@cveNotify
Drupal.org
Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode. The module does not consistently check entity view access. If a user has access to a Blazy-enabled text format, this allows them to render a field from…
🚨 CVE-2026-81166
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
🎖@cveNotify
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
🎖@cveNotify
Drupal.org
Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109
The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic blocks on a display. The route did not check whether the requester was a signage device, nor whether the requested block was one that the module delivers…
🚨 CVE-2026-81167
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
🎖@cveNotify
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
🎖@cveNotify
Drupal.org
Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-103
The Address Suggestion module provides address autocomplete functionality using configured address providers. The module doesn't sufficiently sanitize address suggestion data returned by configured providers, which can lead to a cross-site scripting (XSS)…