Threats Tagged 'packagist-https-packages-drupa'
View all threats tagged with 'packagist-https-packages-drupa'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'packagist-https-packages-drupa'
Click on any threat for detailed analysis and mitigation recommendations
Media folders: This module provides a better UI for managing and selecting Media entities in a folder structure. (CVE-2026-16638)CVE-2026-16638 0 The Media folders module for Drupal provides an improved UI for managing media entities in a folder structure. It suffers from a stored cross-site scripting (XSS) vulnerability due to insufficient sanitization of media item and folder names and descriptions when displayed in the media browser. Exploitation requires the attacker to have permissions to create or edit media items or folders. Versions prior to 1.0.8 are affected. Join the discussion | GCVE Database | 07/22/2026, 17:52:45 UTC Added: 07/22/2026, 23:24:36 UTC |
I18n sso: In a scenario of a multilingual website with different domain names per language, this module enables you to be automatically connected across the… (CVE-2026-16639)CVE-2026-16639 0 The Drupal i18n_sso module for multilingual websites with different domain names per language has a vulnerability that allows an attacker to bypass access control and authenticate as a victim user by exploiting insufficient validation of a short-lived token. This automatic cross-domain login feature can be abused if the attacker originates from the same client IP as the victim. Versions of the module prior to 1.8.0 are affected. No CVSS score is available for this vulnerability. Join the discussion | GCVE Database | 07/22/2026, 17:53:35 UTC Added: 07/22/2026, 23:24:36 UTC |
Search api autocomplete: This module enables you to add autocomplete suggestions for search forms created with the Search API module. (CVE-2026-16640)CVE-2026-16640 0 The Search API Autocomplete module for Drupal enables autocomplete suggestions for search forms created with the Search API module. A test script included with the module is accessible to anonymous users and does not sufficiently validate user input, resulting in a Cross Site Scripting (XSS) vulnerability. This vulnerability is mitigated by the requirement that the web server must be configured to display warning messages to users. Versions of the module prior to 1.12.0 are affected. Join the discussion | GCVE Database | 07/22/2026, 17:55:04 UTC Added: 07/22/2026, 23:24:35 UTC |
Commerce elavon: The security team is marking this project unsupported. (CVE-2026-16641)CVE-2026-16641 0 The Drupal contrib project 'commerce_elavon' is marked as unsupported by its security team due to an unresolved security vulnerability identified as CVE-2026-16641. The maintainer has not fixed the known security issue, and no patch or remediation is currently available. Users of this project are advised to consider taking over maintenance or seek alternatives. Join the discussion | GCVE Database | 07/22/2026, 17:57:03 UTC Added: 07/22/2026, 23:24:35 UTC |
Email login otp: The security team is marking this project unsupported. (CVE-2026-16642)CVE-2026-16642 0 The Drupal contributed project 'email_login_otp' is marked as unsupported by its security team due to an unresolved security issue. The maintainer has not fixed the known vulnerability, and no patch or remediation is currently available. Users of this project should be aware that it is no longer maintained for security and consider alternative solutions or take over maintenance. Join the discussion | GCVE Database | 07/22/2026, 17:57:50 UTC Added: 07/22/2026, 23:24:35 UTC |
Lunr filters: The security team is marking this project unsupported. (CVE-2026-16643)CVE-2026-16643 0 The Drupal contributed project 'lunr_filters' is marked as unsupported by the security team due to an unresolved security vulnerability. The maintainer has not fixed the known issue, and no patch or remediation is currently available. Users of this project should be aware that it is no longer maintained for security and consider alternative solutions or take over maintenance. Join the discussion | GCVE Database | 07/22/2026, 17:59:05 UTC Added: 07/22/2026, 23:24:35 UTC |
Webform rest: This module enables you to retrieve and submit webform submissions via REST endpoints. (CVE-2026-16644)CVE-2026-16644 0 The Drupal webform_rest module versions prior to 4.0.3 contain a vulnerability where the module does not sufficiently verify the parent webform's permissions for creating, viewing, and updating submissions via REST endpoints. This issue affects unsupported versions 4.0.3 and earlier. Exploitation requires the attacker to already have permissions to use the REST resource, which mitigates the risk to some extent. Join the discussion | GCVE Database | 07/22/2026, 18:00:53 UTC Added: 07/22/2026, 23:24:32 UTC |
The Photoswipe Drupal module provides integration for the widely used PhotoSwipe lightbox library to display / zoom images in lightbox galleries… (CVE-2026-16645)CVE-2026-16645 0 The Photoswipe Drupal module integrates the PhotoSwipe lightbox library to display and zoom images in galleries. Versions prior to 3.2.0 do not sufficiently check access permissions when viewing images via the photoswipe image gallery display formatter. This vulnerability primarily affects sites that restrict access to images shown in photoswipe galleries. Public image galleries are not impacted by this issue. Join the discussion | GCVE Database | 07/22/2026, 18:01:57 UTC Added: 07/22/2026, 23:24:32 UTC |
Development environment: The security team is marking this project unsupported. (CVE-2026-15088)CVE-2026-15088 0 The Drupal development environment project has been marked as unsupported by the security team due to an unresolved security issue. The maintainer has not fixed the known vulnerability, and no patch or remediation is currently available. Users are advised that the project is no longer maintained for security purposes and may pose a risk if used without mitigation or replacement. Join the discussion | GCVE Database | 07/22/2026, 18:02:41 UTC Added: 07/22/2026, 23:24:32 UTC |
Showing 1 to 9 of 9 results