Skip to content

Commit 936e6bf

Browse files
1 parent dcb1ddd commit 936e6bf

9 files changed

Lines changed: 435 additions & 0 deletions

File tree

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-084",
4+
"modified": "2026-07-22T17:57:03.000Z",
5+
"published": "2026-07-22T17:57:03.000Z",
6+
"aliases": [
7+
"CVE-2026-16641"
8+
],
9+
"details": "The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: [https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...](https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-maintainer-of-a-project-that-is-unsupported-for-security-reasons)",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/commerce_elavon"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
}
24+
],
25+
"database_specific": {
26+
"constraint": "*"
27+
}
28+
}
29+
],
30+
"database_specific": {
31+
"affected_versions": "*"
32+
}
33+
}
34+
],
35+
"references": [
36+
{
37+
"type": "WEB",
38+
"url": "https://www.drupal.org/sa-contrib-2026-084"
39+
}
40+
],
41+
"credits": []
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-089",
4+
"modified": "2026-07-22T18:02:41.000Z",
5+
"published": "2026-07-22T18:02:41.000Z",
6+
"aliases": [
7+
"CVE-2026-15088"
8+
],
9+
"details": "The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: [https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...](https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-maintainer-of-a-project-that-is-unsupported-for-security-reasons)",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/development_environment"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
}
24+
],
25+
"database_specific": {
26+
"constraint": "*"
27+
}
28+
}
29+
],
30+
"database_specific": {
31+
"affected_versions": "*"
32+
}
33+
}
34+
],
35+
"references": [
36+
{
37+
"type": "WEB",
38+
"url": "https://www.drupal.org/sa-contrib-2026-089"
39+
}
40+
],
41+
"credits": []
42+
}
Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-085",
4+
"modified": "2026-07-22T17:57:50.000Z",
5+
"published": "2026-07-22T17:57:50.000Z",
6+
"aliases": [
7+
"CVE-2026-16642"
8+
],
9+
"details": "The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: [https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...](https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-maintainer-of-a-project-that-is-unsupported-for-security-reasons)",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/email_login_otp"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
}
24+
],
25+
"database_specific": {
26+
"constraint": "*"
27+
}
28+
}
29+
],
30+
"database_specific": {
31+
"affected_versions": "*"
32+
}
33+
}
34+
],
35+
"references": [
36+
{
37+
"type": "WEB",
38+
"url": "https://www.drupal.org/sa-contrib-2026-085"
39+
}
40+
],
41+
"credits": [
42+
{
43+
"name": "Pierre Rudloff (prudloff)",
44+
"contact": [
45+
"https://www.drupal.org/u/prudloff"
46+
]
47+
}
48+
]
49+
}
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-081",
4+
"modified": "2026-07-22T17:53:35.000Z",
5+
"published": "2026-07-22T17:53:35.000Z",
6+
"aliases": [
7+
"CVE-2026-16639"
8+
],
9+
"details": "In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the language domains if you are logged on the main language domain.\n\nThe module doesn't sufficiently validate a short-lived token, allowing an attacker to bypass access control and authenticate as a victim user.\n\nThis vulnerability is mitigated by the fact that an attacker must appear to originate from the same client IP as the victim.",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/i18n_sso"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
},
24+
{
25+
"fixed": "1.8.0"
26+
}
27+
],
28+
"database_specific": {
29+
"constraint": "<1.8.0"
30+
}
31+
}
32+
],
33+
"database_specific": {
34+
"affected_versions": "<1.8.0"
35+
}
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "WEB",
41+
"url": "https://www.drupal.org/sa-contrib-2026-081"
42+
}
43+
],
44+
"credits": [
45+
{
46+
"name": "Drew Webber (mcdruid)",
47+
"contact": [
48+
"https://www.drupal.org/u/mcdruid"
49+
]
50+
}
51+
]
52+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-086",
4+
"modified": "2026-07-22T17:59:05.000Z",
5+
"published": "2026-07-22T17:59:05.000Z",
6+
"aliases": [
7+
"CVE-2026-16643"
8+
],
9+
"details": "The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: [https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-mai...](https://www.drupal.org/node/251466#s-becoming-owner-maintainer-or-co-maintainer-of-a-project-that-is-unsupported-for-security-reasons)",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/lunr_filters"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
}
24+
],
25+
"database_specific": {
26+
"constraint": "*"
27+
}
28+
}
29+
],
30+
"database_specific": {
31+
"affected_versions": "*"
32+
}
33+
}
34+
],
35+
"references": [
36+
{
37+
"type": "WEB",
38+
"url": "https://www.drupal.org/sa-contrib-2026-086"
39+
}
40+
],
41+
"credits": []
42+
}
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-080",
4+
"modified": "2026-07-22T17:52:45.000Z",
5+
"published": "2026-07-22T17:52:45.000Z",
6+
"aliases": [
7+
"CVE-2026-16638"
8+
],
9+
"details": "This module provides a better UI for managing and selecting Media entities in a folder structure.\n\nThe module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/media_folders"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
},
24+
{
25+
"fixed": "1.0.8"
26+
}
27+
],
28+
"database_specific": {
29+
"constraint": "<1.0.8"
30+
}
31+
}
32+
],
33+
"database_specific": {
34+
"affected_versions": "<1.0.8"
35+
}
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "WEB",
41+
"url": "https://www.drupal.org/sa-contrib-2026-080"
42+
}
43+
],
44+
"credits": [
45+
{
46+
"name": "Drew Webber (mcdruid)",
47+
"contact": [
48+
"https://www.drupal.org/u/mcdruid"
49+
]
50+
}
51+
]
52+
}
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-088",
4+
"modified": "2026-07-22T18:01:57.000Z",
5+
"published": "2026-07-22T18:01:57.000Z",
6+
"aliases": [
7+
"CVE-2026-16645"
8+
],
9+
"details": "The Photoswipe Drupal module provides integration for the widely used [PhotoSwipe lightbox library](https://photoswipe.com/) to display / zoom images in lightbox galleries using the provided image formatters.\n\nThe module didn't sufficiently check access permissions, when viewing an image using the photoswipe image gallery display formatter, in versions < 3.0.4 (Drupal 8) or < 3.2.0 (Drupal 9 / Drupal 10).\n\nThis vulnerability is mitigated by the fact that it only affects sites limiting access to the images shown in photoswipe (the most common use case for photoswipe lightboxes public images).",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/photoswipe"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
},
24+
{
25+
"fixed": "3.2.0"
26+
}
27+
],
28+
"database_specific": {
29+
"constraint": "<3.2.0"
30+
}
31+
}
32+
],
33+
"database_specific": {
34+
"affected_versions": "<3.2.0"
35+
}
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "WEB",
41+
"url": "https://www.drupal.org/sa-contrib-2026-088"
42+
}
43+
],
44+
"credits": [
45+
{
46+
"name": "Aleksi Peebles (aleksip)",
47+
"contact": [
48+
"https://www.drupal.org/u/aleksip"
49+
]
50+
}
51+
]
52+
}
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.7.0",
3+
"id": "DRUPAL-CONTRIB-2026-082",
4+
"modified": "2026-07-22T17:55:04.000Z",
5+
"published": "2026-07-22T17:55:04.000Z",
6+
"aliases": [
7+
"CVE-2026-16640"
8+
],
9+
"details": "This module enables you to add autocomplete suggestions for search forms created with the [Search API module](/project/search_api).\n\nThe module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.\n\nThis vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.",
10+
"affected": [
11+
{
12+
"package": {
13+
"ecosystem": "Packagist:https://packages.drupal.org/8",
14+
"name": "drupal/search_api_autocomplete"
15+
},
16+
"severity": [],
17+
"ranges": [
18+
{
19+
"type": "ECOSYSTEM",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
},
24+
{
25+
"fixed": "1.12.0"
26+
}
27+
],
28+
"database_specific": {
29+
"constraint": "<1.12.0"
30+
}
31+
}
32+
],
33+
"database_specific": {
34+
"affected_versions": "<1.12.0"
35+
}
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "WEB",
41+
"url": "https://www.drupal.org/sa-contrib-2026-082"
42+
}
43+
],
44+
"credits": [
45+
{
46+
"name": "Elar Lang (elarlang)",
47+
"contact": [
48+
"https://www.drupal.org/u/elarlang"
49+
]
50+
}
51+
]
52+
}

0 commit comments

Comments
 (0)