Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Drupal Security Team

@drupalsecurity@drupal.community
mastodon 4.7.2
  • Open on drupal.community

Republish Drupal Security Advisories & related news. Follow Drupal Security Team. Contact @greggles@drupal.community to get RT. DM & mentions not actively monitored. https://drupal.org/node/101494

551 Followers
5 Following
30 Posts
Joined December 16, 2022
Source of Advisories:
https://www.drupal.org/security/
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago
Replying to
The Drupal Security Team estimates that up to 5% of Drupal sites may be vulnerable to this highly critical issue. Furthermore, a majority of Drupal sites may also be affected by the Symfony and Twig security advisories published today, so all sites should update soon. Details in the advisory above.
5
0
4
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Drupal-related security releases today include those referenced below. You can start updating dependencies from Symfony and doing testing steps now.

5
1
5
1
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago
Replying to
Site owners are encouraged to get their sites ready for a release of Drupal core that may affect them. Site owners should make upgrades easier (e.g. update to the most recent release available, improve deployment automation, improve automated testing) given the current security climate.
3
1
7
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039

https://www.drupal.org/sa-contrib-2026-039

drupal.org
1
0
1
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 18mo ago
Replying to
Responses are welcome to the survey for the next few days, but any responses delivered today will be included in the Drupalcon Presentation tomorrow!
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 13mo ago

Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100

https://www.drupal.org/sa-contrib-2025-100

drupal.org
0
0
1
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047

https://www.drupal.org/sa-contrib-2026-047

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Composer - Critical - Unsupported - SA-CONTRIB-2026-046

https://www.drupal.org/sa-contrib-2026-046

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045

https://www.drupal.org/sa-contrib-2026-045

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044

https://www.drupal.org/sa-contrib-2026-044

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043

https://www.drupal.org/sa-contrib-2026-043

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042

https://www.drupal.org/sa-contrib-2026-042

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041

https://www.drupal.org/sa-contrib-2026-041

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

TacJS - Moderately critical - Improper Access Control - SA-CONTRIB-2026-040

https://www.drupal.org/sa-contrib-2026-040

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038

https://www.drupal.org/sa-contrib-2026-038

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037

https://www.drupal.org/sa-contrib-2026-037

drupal.org
0
0
1
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Colorbox Inline - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-036

https://www.drupal.org/sa-contrib-2026-036

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035

https://www.drupal.org/sa-contrib-2026-035

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 4mo ago

Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034

https://www.drupal.org/sa-contrib-2026-034

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 5mo ago

Obfuscate - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-033

https://www.drupal.org/sa-contrib-2026-033

drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 3mo ago
Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066 https://www.drupal.org/sa-contrib-2026-066
drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 2mo ago
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011 https://www.drupal.org/sa-core-2026-011
drupal.org
0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 2w ago
Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176 https://www.drupal.org/sa-contrib-2026-176
Drupal.org

Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176

The Cloud module enables users to manage cloud infrastructure through Drupal. The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.

0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 2w ago
Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183 https://www.drupal.org/sa-contrib-2026-183
Drupal.org

Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183

This module enables sites to block access for the administrative user account (user 1) or users with the administrator role. The module does not sufficiently enforce these access restrictions across all supported authentication mechanisms. As a result, a blocked administrative user may still be able to authenticate through certain alternative authentication methods. This

0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 2w ago
Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188 https://www.drupal.org/sa-contrib-2026-188
Drupal.org

Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188

This module enables you to combine multiple image styles into a single image derivative. The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service. Sites are affected simply by having the

0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 2w ago
Webform REST - Less critical - Access bypass - SA-CONTRIB-2026-186 https://www.drupal.org/sa-contrib-2026-186
Drupal.org

Webform REST - Less critical - Access bypass - SA-CONTRIB-2026-186

This module enables you to retrieve and submit webforms via REST. The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.

0
0
0
0
Open post
Drupal Security Team @drupalsecurity@drupal.community
· 2w ago
Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191 https://www.drupal.org/sa-contrib-2026-191
Drupal.org

Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191

The Diba Carousel Slider adds a Bootstrap carousel slider block that can be used directly without creating a View or custom integration. When the "Allow HTML description" option is enabled, slide descriptions are rendered using the raw stored field value instead of the field's rendered output. This bypasses Drupal's text format filtering and output sanitization mechanisms.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:09:04 UTC