Drupal Aid
Drupal Support and Maintenance Services. We love Drupal and provide Unlimited support, maintenance, Drupal Support and Maintenance Services
09/23/2026
Big day on the Drupal security page. Sixteen contributed modules got security releases today, for Drupal 10 and 11. Four have critical problems, so start there.
Webform 6.3.1 is the one most sites will actually have. This single release closes 20 advisories. The worst is a critical remote code ex*****on bug: when a webform uses a custom multiple-value item format that includes submission-value tokens, someone can submit text that gets evaluated as template code when the submission is displayed. Depending on the site, that can leak information, plant a script in the page, or run code on the server. The rest of the batch is access bypass, cross-site scripting, a server-side request forgery and a denial of service.
Cloud 7.0.1 (two critical advisories). In the Kubernetes submodule, Git branch names and repository URLs are passed to shell commands without proper cleaning, so a user who can add or edit cloud server templates could run commands on your server. You're only exposed if that submodule is enabled and Git is on the box.
Project Browser 2.1.5. The screens that apply recipes and enable modules don't guard against cross-site request forgery. An attacker could get a logged-in admin to click a link that installs something without meaning to.
Tawk.to 3.0.4. Same class of bug in the live chat integration: a logged-in user can be tricked into actions they never intended.
The moderately critical group:
AI CKEditor 1.4.3: Twig template injection in some AI rules can pull out confidential system data.
Combined image style 1.0.7: anonymous visitors can generate image derivatives without a valid token, which can be used to overload the server. Having the module installed is enough, even with no combined styles set up. Public files only.
Commerce Decoupled Checkout 1.8.0: the order creation endpoint lets unsafe properties be set on an order.
CookieCuttr 2.0.3: stored cross-site scripting through the admin form. Needs the "administer cookiecuttr" permission.
CSS Usage Analyzer 1.0.2: the save endpoint accepts forged or repeated submissions.
Diba carousel slider 3.1.1: slide descriptions skip Drupal's text filtering when "Allow HTML description" is on, which opens the door to cross-site scripting.
Editoria11y Accessibility Checker 2.2.23 or 3.0.9: a permission labeled as "view" actually grants edit and delete on the module's data.
Mermaid Diagram Field 1.0.10: modal diagram content isn't access-checked properly.
REST & JSON API Authentication 3.2.0: some API requests skip the authentication check.
Smart Content 3.2.1: the Smart Content Block AJAX endpoint can show access-restricted blocks to the wrong users. Views blocks aren't affected.
Stop administrator login 1.6.0: a blocked admin account can still sign in through some less common login methods, provided the attacker has that account's password.
And one less critical: Webform REST 4.2.1 doesn't check permissions properly when returning webform elements and fields.
If none of these modules are on your site, there's nothing for you to do today.
09/16/2026
Quick one for anyone running Drupal 10 or 11: update core.
Today's advisory, SA-CORE-2026-013, covers a cross-site scripting bug in the CKEditor library that comes with Drupal. The versions you want are 11.4.7, 11.3.17 or 10.6.17, depending on which branch you're on.
Why bother? A user with permission to write content could slip in code that fires when an administrator edits that content. The attacker never touches the editor directly. On sites where several people contribute content, that's a realistic path to an admin account.
Sites that don't use CKEditor for WYSIWYG editing aren't affected by this one. Older, unsupported core branches won't get a fix, so this is also a good nudge to get onto a supported release.
09/09/2026
If you run any of these ten Drupal modules, today is an update day. Everything below affects Drupal 10 and 11.
Update now, in rough order of how much it matters:
amazee.ai Private AI Provider to 1.4.3. SQL injection through unsanitized filter values in the Postgres/pgvector backend. Critical.
CSP log to 1.0.2. SQL injection in the report endpoint, reachable by anyone holding the "Access CSP reports" permission. Critical.
Taxonomy Term Glossary to 4.6.0. Anonymous visitors could read any taxonomy term through the JSON endpoint, unpublished ones included. Critical.
Ultimate Table Field to 2.0.1, or 1.1.1 if you are on the 1.x branch. Anonymous visitors could open the cell editor dialog and upload pdf, doc or docx files to the server. Critical.
CAS Server to 2.1.3. Open redirect during login.
Feed Block to 3.0.2, or 2.0.2 on 2.x. Stored cross-site scripting in the generated feed.
Key auth to 2.2.4. Missing per-user caching could expose one user's API key to another with the same permissions.
SafeDelete to 1.0.88. Stored cross-site scripting through node titles on the orphaned content report.
SAML SSO Service Provider to 3.2.0. Unvalidated identity provider metadata URLs allow server side request forgery.
One of the ten has no fix. Patreon has been marked unsupported by the security team over an issue the maintainer never resolved. There is no version to update to, so the answer there is to plan a move away from the module, or volunteer to maintain it.
A quick way to check where you stand: log in as an administrator and open Reports, then Available updates. If none of these module names show up, this week does not affect you.
09/02/2026
Fourteen Drupal security advisories went out today. Four are rated critical, and those are the ones to deal with first.
Calculate Working Days (2.0.3) left its settings form open to people who should not be able to reach it.
Email Verification / SMS Verification / OTP Verification (2.4.0) has a reflected cross-site scripting hole that does not require an attacker to be logged in at all. That combination is why it earned a critical rating.
Jsonapi Role Access (2.0.2) is meant to lock JSON:API routes down by role. A request shaped like an XMLHttpRequest slipped past those checks.
Unpublished Node Permissions (1.8.0) was granting view access to published content in a way that overrode other access rules a site had set up.
The remaining ten are moderately critical.
Mailer Plus Log (1.2.7) is the one I would not sit on. It logged account emails with their one-time login links still readable, so anyone allowed to view the mail log could grab a login link for any account, user 1 included.
Media Library Importer (2.1.6) accepted any folder path the web user could read and republished the files it found into the public files directory. Private files could end up downloadable by anyone.
Monobank payment API (1.0.3) processed payment webhooks without checking the signature first.
Advanced Search (2.4.5) and Islandora (2.19.0) share the same AJAX endpoint flaw, where a guessed block ID could return restricted block content.
AI (1.4.8) and AI translate (1.4.1) skipped access checks on referenced entities during translation.
Component blocks (1.2.7) and PhotoSwipe (5.0.9) both pass user input through without enough sanitising, which opens the door to cross-site scripting.
Webform Submissions Delete (1.2.0) did not properly restrict access to its bulk delete form.
All of these apply to Drupal 10 and 11. If you do not run the module, there is nothing to do.
08/26/2026
If you maintain a Drupal site, here is your to-do list from today's security releases. Fourteen advisories, all contrib, nothing for core.
Check your installed modules against this list and update whatever matches:
Entity API to 1.8.0
Blazy to 3.0.18
Slick Carousel to 2.1.0
Content Moderation Notifications to 3.9.0
Commerce CyberSource to 1.10.0
DXPR Builder to 2.8.1
Data field to 2.0.13
Digital Signage Framework to 2.6.1
Disable Login Page to 1.1.4
Entity PDF to 2.1.5
LDAP / Active Directory Integration to 2.2.1
Address Suggestion to 1.0.25
CAPTCHA Protected Page to 1.0.2
Monster Menus to 9.5.3
Thirteen are rated moderately critical. Blazy is less critical. Monster Menus is a Drupal 9 release; the rest are for 10 and 11.
Start with Entity API if it shows up in your composer file. It is a common dependency, so plenty of sites are running it without anyone having deliberately installed it, and an information disclosure bug in something that quiet is easy to leave sitting there.
Nothing on this list applies to modules you don't have installed, so a short audit is all most sites need.
Nothing to patch in Drupal this week. Three modules to check for instead.
Start here: search your site for Gammu SMS Daemon, Link content parser, and Screenshot. If none of them are installed, you are done reading.
Still here? Each of those was marked unsupported by the Drupal security team today, and there is no updated release to install. The security team does that when a genuine flaw gets reported and the maintainer does not fix it. Every version of the module carries the problem.
What that means for you depends on the module. Screenshot picked up two CVEs, Gammu SMS Daemon picked up three, and Link content parser picked up one. All three advisories are rated critical, though the exploit is listed as theoretical, so there is time to plan rather than panic.
The work is the same in each case. Figure out which part of your site depends on the module, look for a maintained alternative that does the same job, migrate whatever configuration or content sits behind it, then uninstall. Leaving an unsupported module in place because nothing has broken yet just means the clock is running.
One thing people forget: an unsupported project can find a new maintainer and come back into coverage. If the module matters enough to your site, adopting it yourself is a real option, and drupal.org documents how that works.
08/12/2026
Five security advisories came out for Drupal contributed modules today. All five are rated moderately critical, and there was no core release this week.
Quick Tabs (4.3.1) is the one worth checking first, since it turns up on a lot of sites. When it rendered node and block tabs it treated a neutral access result as permission granted, and it skipped the access check on reusable custom blocks entirely. In practice that meant unpublished content could appear to visitors who had no right to see it. What limits the damage is that someone with the "administer quicktabs" permission picks the content when the tab is set up, so an attacker cannot choose what gets exposed.
Commerce PayPal (2.1.3) did not properly validate the transaction result in some cases, which allowed a malicious user to mark an order as paid when no payment had gone through. This only affects sites on the Payflow Link gateway. If you take money through that gateway, move this one to the top of your list.
External Authentication (2.0.13) stores and looks up the mapping between a Drupal account and an external identity provider. Under certain MySQL and MariaDB collation settings it did not match those external identity values exactly, so a login could resolve to the wrong account.
Entity Share Websub (1.1.2) shares content between sites in a hub and subscriber setup. Some of its inputs went unvalidated, which opened it to server-side request forgery.
Diff (2.1.1) did not restrict access to revision comparisons on non-node entities. An attacker needs a role with permission to view the entity in the first place, so the reach here is narrow.
If you don't run any of these five modules, there is nothing for you to do this week. If you do, the fixed releases are listed above and the full advisories are on drupal.org.
Short to-do list out of Drupal today, assuming any of this applies to you.
Update Token Content Access to 3.1.2. The module protects content behind access tokens, and the way it checked those tokens gave away timing information. A determined attacker could measure the response times, narrow down a working token from that, and reach content meant to stay private. Knowing the URL is a prerequisite, so it isn't trivial to pull off, but the fix is available and easy to take.
Uninstall Disable Login Page. Uninstall Powerful Surveys. Both were marked unsupported today, which is the security team's way of saying there is a real problem in the code, the maintainer has gone quiet, and no patch is coming. Both are rated critical. Leaving them installed means running known-broken code with no end date on it. If either does something you rely on, start looking for a replacement now. Anyone willing to take over maintaining them can, and the advisories explain how.
Not running any of them? Then there is nothing here for you to do.
If you look after a Drupal site, today's a good day to check your updates page.
Ten security advisories went out. Most are moderately critical and only matter if you've got the module installed, but two are worth doing sooner rather than later.
Internationalization Single Sign-On has a critical access bypass. On multilingual sites with a domain per language it could let someone see areas they shouldn't. Version 1.8.0 fixes it.
Core has a cross-site scripting hole in Layout Builder, where block labels weren't properly sanitised. Depending on your version you want 10.6.13, 11.3.14 or 11.4.4.
Then update these if you use them:
PhotoSwipe to 3.0.4
UI Patterns to 2.0.17
Media Folders to 1.0.8
Webform REST to 4.1.0
Search API Autocomplete to 1.12.0
AI SEO/GEO Analyzer to 1.1.3
ECA to 3.1.4 or 2.1.20
QA Accounts is a different case. It's lost its security advisory coverage, so no more security fixes will be issued for it. It logs you in with well known credentials and doesn't belong on a production site, so remove it rather than waiting for a patch.
None of this affects modules you don't have installed.
07/15/2026
Drupal released a core security update today (SA-CORE-2026-010, 011 & 012).
Because this is Drupal core — not an add-on module — EVERY Drupal 10 and 11 site is affected.
The issue: cross-site scripting (XSS) and information-disclosure vulnerabilities that could let an attacker run malicious code in visitors' browsers or expose data.
What to do:
- Drupal 10 sites: update core to 10.6.13
- Drupal 11 sites: update core to 11.4.4
- Rated "Moderately Critical" by the Drupal Security Team
Click here to claim your Sponsored Listing.
Telephone
Website
Address
Alerts
Be the first to know and let us send you an email when Drupal Aid posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.