Drupal Security Team

Republish Drupal Security Advisories & related news. Follow Drupal Security Team. Contact @greggles to get RT. DM & mentions not actively monitored. drupal.org/node/101494

2025-07-02

Config Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086

drupal.org/sa-contrib-2025-086

2025-07-02

Two-factor Authentication (TFA) - Less critical - Access bypass - SA-CONTRIB-2025-085

drupal.org/sa-contrib-2025-085

2025-06-25

Paragraphs table - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-084

drupal.org/sa-contrib-2025-084

2025-06-25

Simple XML sitemap - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-083

drupal.org/sa-contrib-2025-083

2025-06-25

Enterprise MFA - TFA for Drupal - Critical - Access bypass - SA-CONTRIB-2025-082

drupal.org/sa-contrib-2025-082

2025-06-25

CKEditor5 Youtube - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-081

drupal.org/sa-contrib-2025-081

2025-06-25

Klaro Cookie & Consent Management - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-080

drupal.org/sa-contrib-2025-080

2025-06-25

Open Social - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-079

drupal.org/sa-contrib-2025-079

2025-06-25

GLightbox - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-078

drupal.org/sa-contrib-2025-078

2025-06-25

Toc.js - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-077

drupal.org/sa-contrib-2025-077

2025-05-28

COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-076

drupal.org/sa-contrib-2025-076

2025-05-28

COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-075

drupal.org/sa-contrib-2025-075

2025-05-28

etracker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-074

drupal.org/sa-contrib-2025-074

2025-05-28

Simple Klaro - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-073

drupal.org/sa-contrib-2025-073

2025-05-28

EU Cookie Compliance (GDPR Compliance) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-072

drupal.org/sa-contrib-2025-072

2025-05-28

Simple Klaro - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-071

drupal.org/sa-contrib-2025-071

2025-05-28

Bookable Calendar - Less critical - Access bypass - SA-CONTRIB-2025-070

drupal.org/sa-contrib-2025-070

2025-05-21

Lightgallery - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-069

drupal.org/sa-contrib-2025-069

2025-05-21

Admin Audit Trail - Less critical - Denial of Service - SA-CONTRIB-2025-068

drupal.org/sa-contrib-2025-068

2025-05-21

Commerce Alphabank Redirect - Moderately critical - Access bypass - SA-CONTRIB-2025-067

drupal.org/sa-contrib-2025-067

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst