WebAssembly is a secure and efficient binary format that allows safe execution of code. It follows a deny-by-default security approach, requiring explicit authorization for accessing external resources.
...more
Although Drupal has a reputation for being a secure CMS, it is not immune to security vulnerabilities, and website owners need to take measures to keep their website safe.
...more
The process of loading fonts from the Google CDN used to expose the users’ Personally Identifiable Information (PII) such as IP addresses to Google. German courts have ruled that this leakage amounts to violation of privacy and threatened DXPR theme users with penalties.
...more
The threat actors deploying the malware rely on server misconfigurations associated with popular web frame works including Drupal. Other frameworks like Wordpress, Laravel, Joomla, Magento are also targeted by AlienFox.
...more
Multiple vulnerabilities are possible if an untrusted user has access to write Twig code, including potential unauthorized read access to private files, the contents of other files on the server, or database credentials.
...more
The module doesn't sufficiently verify that it's communicating with the correct server when using the Elavon (On-site) payment gateway, to correct this you can install the latest version.
...more
Multiple vulnerabilities have been detected in Drupal Core which can allow remote attackers to execute arbitrary code, access sensitive information, and cause cross-site scripting attacks on the targeted systems.
...more