Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'packagist-https-packages-drupa'

View all threats tagged with 'packagist-https-packages-drupa'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: packagist-https-packages-drupa

Threats Tagged 'packagist-https-packages-drupa'

Click on any threat for detailed analysis and mitigation recommendations

Media folders: This module provides a better UI for managing and selecting Media entities in a folder structure. (CVE-2026-16638)CVE-2026-16638
0

The Media folders module for Drupal provides an improved UI for managing media entities in a folder structure. It suffers from a stored cross-site scripting (XSS) vulnerability due to insufficient sanitization of media item and folder names and descriptions when displayed in the media browser. Exploitation requires the attacker to have permissions to create or edit media items or folders. Versions prior to 1.0.8 are affected.

Join the discussion
I18n sso: In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the… (CVE-2026-16639)CVE-2026-16639
0

The Drupal i18n_sso module for multilingual websites with different domain names per language has a vulnerability that allows an attacker to bypass access control and authenticate as a victim user by exploiting insufficient validation of a short-lived token. This automatic cross-domain login feature can be abused if the attacker originates from the same client IP as the victim. Versions of the module prior to 1.8.0 are affected. No CVSS score is available for this vulnerability.

Join the discussion
Search api autocomplete: This module enables you to add autocomplete suggestions for search forms created with the Search API module. (CVE-2026-16640)CVE-2026-16640
0

The Search API Autocomplete module for Drupal enables autocomplete suggestions for search forms created with the Search API module. A test script included with the module is accessible to anonymous users and does not sufficiently validate user input, resulting in a Cross Site Scripting (XSS) vulnerability. This vulnerability is mitigated by the requirement that the web server must be configured to display warning messages to users. Versions of the module prior to 1.12.0 are affected.

Join the discussion
Commerce elavon: The security team is marking this project unsupported. (CVE-2026-16641)CVE-2026-16641
0

The Drupal contrib project 'commerce_elavon' is marked as unsupported by its security team due to an unresolved security vulnerability identified as CVE-2026-16641. The maintainer has not fixed the known security issue, and no patch or remediation is currently available. Users of this project are advised to consider taking over maintenance or seek alternatives.

Join the discussion
Email login otp: The security team is marking this project unsupported. (CVE-2026-16642)CVE-2026-16642
0

The Drupal contributed project 'email_login_otp' is marked as unsupported by its security team due to an unresolved security issue. The maintainer has not fixed the known vulnerability, and no patch or remediation is currently available. Users of this project should be aware that it is no longer maintained for security and consider alternative solutions or take over maintenance.

Join the discussion
Lunr filters: The security team is marking this project unsupported. (CVE-2026-16643)CVE-2026-16643
0

The Drupal contributed project 'lunr_filters' is marked as unsupported by the security team due to an unresolved security vulnerability. The maintainer has not fixed the known issue, and no patch or remediation is currently available. Users of this project should be aware that it is no longer maintained for security and consider alternative solutions or take over maintenance.

Join the discussion
Webform rest: This module enables you to retrieve and submit webform submissions via REST endpoints. (CVE-2026-16644)CVE-2026-16644
0

The Drupal webform_rest module versions prior to 4.0.3 contain a vulnerability where the module does not sufficiently verify the parent webform's permissions for creating, viewing, and updating submissions via REST endpoints. This issue affects unsupported versions 4.0.3 and earlier. Exploitation requires the attacker to already have permissions to use the REST resource, which mitigates the risk to some extent.

Join the discussion
The Photoswipe Drupal module provides integration for the widely used PhotoSwipe lightbox library to display / zoom images in lightbox galleries… (CVE-2026-16645)CVE-2026-16645
0

The Photoswipe Drupal module integrates the PhotoSwipe lightbox library to display and zoom images in galleries. Versions prior to 3.2.0 do not sufficiently check access permissions when viewing images via the photoswipe image gallery display formatter. This vulnerability primarily affects sites that restrict access to images shown in photoswipe galleries. Public image galleries are not impacted by this issue.

Join the discussion
Development environment: The security team is marking this project unsupported. (CVE-2026-15088)CVE-2026-15088
0

The Drupal development environment project has been marked as unsupported by the security team due to an unresolved security issue. The maintainer has not fixed the known vulnerability, and no patch or remediation is currently available. Users are advised that the project is no longer maintained for security purposes and may pose a risk if used without mitigation or replacement.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: packagist-https-packages-drupa
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses