Drupal Security Team
drupalsecurity.bsky.social
Drupal Security Team
@drupalsecurity.bsky.social
Automatically post Drupal Security Advisories & related news. Follow Drupal Security Team.
@gknaddison.bsky.social
to get RT. DM & mentions not monitored. https://drupal.org/node/101494
Simple multi step form - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-116 Read post
November 5, 2025 at 6:11 PM
Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-115 Read post
November 5, 2025 at 6:11 PM
Normal Drupal core security window rescheduled for November 12, 2025 due to DrupalCon - PSA-2025-11-03 Read post
November 3, 2025 at 3:44 PM
Simple OAuth (OAuth2) & OpenID Connect - Critical - Access bypass - SA-CONTRIB-2025-114 Read post
October 29, 2025 at 5:08 PM
CivicTheme Design System - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-113 Read post
October 22, 2025 at 5:08 PM
CivicTheme Design System - Moderately critical - Information disclosure - SA-CONTRIB-2025-112 Read post
October 22, 2025 at 5:08 PM
Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111 Read post
September 24, 2025 at 5:36 PM
Currency - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-110 Read post
September 24, 2025 at 5:36 PM
Umami Analytics - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-109 Read post
September 24, 2025 at 5:36 PM
Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-108 Read post
September 24, 2025 at 5:36 PM
Plausible tracking - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-107 Read post
September 24, 2025 at 5:21 PM
JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106 Read post
September 24, 2025 at 5:21 PM
Third-Party Libraries and Supply Chains - PSA-2025-09-17 Read post
September 17, 2025 at 8:43 PM
Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105 Read post
September 3, 2025 at 5:07 PM
Owl Carousel 2 - Critical - Unsupported - SA-CONTRIB-2025-104 Read post
August 27, 2025 at 5:21 PM
API Key manager - Critical - Unsupported - SA-CONTRIB-2025-103 Read post
August 27, 2025 at 5:21 PM
Synchronize composer.json With Contrib Modules - Critical - Unsupported - SA-CONTRIB-2025-102 Read post
August 27, 2025 at 5:21 PM
Protected Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-101 Read post
August 27, 2025 at 5:21 PM
Facets - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-100 Read post
August 27, 2025 at 5:21 PM
Facets - Moderately critical - Information Disclosure - SA-CONTRIB-2025-099 Read post
August 27, 2025 at 5:21 PM
Authenticator Login - Moderately critical - Access bypass - SA-CONTRIB-2025-098 Read post
August 27, 2025 at 5:21 PM
Layout Builder Advanced Permissions - Moderately critical - Access bypass - SA-CONTRIB-2025-097 Read post
August 13, 2025 at 5:44 PM
Authenticator Login - Highly critical - Access bypass - SA-CONTRIB-2025-096 Read post
August 13, 2025 at 5:44 PM
AI SEO Link Advisor - Less critical - Server-side Request Forgery - SA-CONTRIB-2025-095 Read post
August 6, 2025 at 5:29 PM
GoogleTag Manager - Moderately critical - Cross-site scripting - SA-CONTRIB-2025-094 Read post
July 30, 2025 at 5:28 PM