Ten Drupal Contrib Advisories Split Between Fixes and Unsupported Projects

Upgrade Paths for Five Projects, Uninstall Notices for Five Others
Pale pink Drupal security graphic with a falling code pattern. the Elavon Merchant Services logo. a folder marked with the Drupal logo. and a search suggestion panel. Text reads "SECURITY". "Drupal Security Advisory Roundup". "Ten Advisories. Five Fixes. Five Unsupported Projects.". "Access bypass. cross site scripting. and maintenance risks across contributed modules". "Search". "drupal". "drupal". "drupal 8". "drupalcon". "drupalista". "Follow us on". and "The DropTimes".

Site owners received ten contributed-project security advisories from the Drupal Security Team on 22 July 2026. Five projects received fixed releases, while five were marked unsupported because known security issues had not been fixed. Six advisories are rated Critical and four are rated Moderately Critical. None concerns Drupal core.

The advisories require different responses despite appearing in the same release window. Supported projects need upgrades, unsupported projects must be removed or replaced, and a separate public service announcement places QA Accounts outside security advisory coverage. The batch therefore requires maintainers to examine project status and configuration-specific exposure rather than prioritising by severity labels alone.

All ten advisories carry the exploit rating E:Theoretical, which records that no public exploit code or documentation was known when the advisories were issued. That rating does not mean exploitation is impossible. Installed versions, enabled functionality, permissions, server configuration, and the availability of a supported release still determine the action required for each site.

Five Critical advisories mark Development Environment, Lunr exposed filters, Email Login OTP, Commerce Elavon, and PanKM unsupported. Each advisory assigns a risk score of 16 out of 25 and the vector AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:All. All versions are affected, and the Drupal Security Team recommends uninstalling each project.

The matching scores do not establish that the five projects contain the same vulnerability. The advisories do not disclose the underlying technical mechanisms. Their common operational significance is that no covered release is available for a known security issue, leaving removal or replacement as the recommended response.

Three fixed vulnerabilities concern access control. PhotoSwipe did not sufficiently check image-access permissions when using its gallery display formatter, although the issue affects only sites where the displayed images are restricted. Sites using the Drupal 8-compatible branch should upgrade to 3.0.4, while sites on the Drupal 9 or Drupal 10 branches should use 3.2.0 or later.

Webform REST did not sufficiently enforce the parent webform’s create, view, and update permissions when its REST resources were used. Exploitation requires permission to use the REST resource, and the advisory applies to already-unsupported releases through 4.0.3. Affected sites should upgrade to 4.1.0 or later; version 4.2.0 already contains the fix.

Internationalization Single Sign-On did not sufficiently validate a short-lived token used for authentication across language domains. An attacker could authenticate as another user but would need to appear to originate from the victim’s client IP address. Sites should upgrade to 8.x-1.8.

The three modules expose different functions, but each extends access to protected Drupal data or identity through an integration boundary. PhotoSwipe adds an image formatter, Webform REST exposes submission operations through REST endpoints, and Internationalization Single Sign-On transfers authentication between domains. Those additional routes must preserve the permissions and trust assumptions of the underlying Drupal systems.

The other two fixed advisories concern cross-site scripting. Search API Autocomplete included a test script that anonymous users could access and that did not sufficiently validate input. Exploitation also requires the web server to display warning messages, and sites should upgrade to 8.x-1.12 while ensuring that PHP errors are not displayed publicly.

Media Folders did not sufficiently sanitise media and folder names and descriptions before displaying them in the media browser. A user with permission to create or edit those records could introduce stored cross-site scripting. Version 1.0.8 contains the fix.

These vulnerabilities show that development utilities, diagnostic output, integration endpoints, and administrative interfaces can form part of a site’s attack surface. Exposure depends on specific conditions, including restricted images, REST permissions, displayed server warnings, trusted client addresses, and content-management permissions. A project’s total installation count or headline risk score cannot establish whether an individual site is exploitable.

The QA Accounts announcement is not an additional vulnerability advisory. The module permits access through well-known username and password combinations for testing, and its maintainers have removed security advisory coverage. It is intended only for development or staging systems that are not accessible from the internet, and the announcement directs site owners to ensure that it is not enabled on any publicly available site.

The release window therefore presents three maintenance actions. Supported affected modules need upgrades, unsupported projects need removal or replacement, and QA Accounts must remain outside publicly reachable environments. Reviews limited to Drupal core or severity ratings can miss risks created by abandoned dependencies, obsolete branches, alternative data paths, development scripts, and privileged interfaces.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events