The striking number is only part of the result. NOVA also reports thousands of access-control, injection, path-traversal, and dependency-related findings that conventional crash-focused automation is less suited to uncover.
...more
Five Moderately Critical labels do not describe one kind of failure. Earlier Drupal disclosures show where payment, identity, and outbound-request risks recur, and where the similarities stop at the advisory classification.
...more
A July security update fixed insufficient sanitisation of markup passed to UI Patterns components. Follow-up work moved escaping closer to render time, while UI Patterns 2.0.19 is now the current stable release.
...more
The same severity label does not mean the same exposure. Site maintainers need to distinguish administrator-dependent XSS from a permission-based field-editing bypass when assessing the two updates.
...more
A single advisory window can demand upgrades, removals, and tighter environment controls. The correct response depends on support status and exposure conditions, not the severity label alone.
...more
The vulnerabilities depend on different permissions and configurations, but supported sites should still install the appropriate security release. Maintainers of contributed modules that handle HTMX attributes or implement custom stream wrappers should review the accompanying hardening.
...more
The batch presents three response paths to Drupal site teams: uninstall unsupported projects, patch active modules, and review where untrusted or generated content reaches the rendering layers.
...more