[CIVN-2026-0447] Multiple Vulnerabilities in Drupal Modules

By Published On: September 10, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Drupal Modules


Original Issue Date:September 09, 2026


Severity Rating: HIGH


Software Affected


Webform Submissions Delete module prior to versions 1.2.0

Unpublished Node Permissions module prior to versions 1.8.0

PhotoSwipe – Responsive JavaScript Modal Image Gallery module versions prior to 5.0.9

Monobank payment API module versions prior to 1.0.3

Media Library Importer module versions prior to 2.1.6

Mailer Plus Log module versions prior to 1.2.7

Jsonapi Role Access module versions prior to 2.0.2

Islandora versions module versions prior to 2.19.0

Email Verification / SMS Verification / OTP Verification module versions prior to 2.4.0

Component blocks module versions prior to 1.2.7

Calculate Working Days module versions prior to 2.0.3

AI translate module versions prior to 1.3.2

AI translate module versions from versions 1.4.0 through 1.4.1

AI (Artificial Intelligence) module versions prior to 1.3.13

AI (Artificial Intelligence) module versions from 1.4.0 through 1.4.8

Advanced Search module versions prior to 2.4.5

Overview


Multiple vulnerabilities have been reported in various contributed modules of Drupal, which could allow an attacker to bypass access controls, disclose sensitive information, execute malicious scripts, manipulate application data, or compromise user accounts.


Target Audience:

Individuals and end-user organizations using Drupal Modules.


Risk Assessment:

High risk of unauthorized access, sensitive information disclosure, malicious script execution, and account compromise..


Impact Assessment:

Potential compromise of the confidentiality, integrity, and availability of affected Drupal websites.


Description


Drupal is an open-source content management system (CMS) used to build, manage, and publish websites and digital applications. Drupal modules are essential extensions that enhance Drupals core functionality by adding features such as content management, user authentication, search, APIs, security controls, and third-party integrations.


These vulnerabilities exist due to improper access controls, inadequate input validation, and insufficient authorization checks. An attacker could exploit these vulnerabilities by executing crafted requests or malicious input.


Successful exploitation could result in unauthorized access, sensitive information disclosure, cross site scripting, data manipulation, or account compromise.


Solution


Upgrade to the latest versions as mentioned in the advisory:

https://www.drupal.org/sa-contrib-2026-118


https://www.drupal.org/sa-contrib-2026-119


https://www.drupal.org/sa-contrib-2026-120


https://www.drupal.org/sa-contrib-2026-121


https://www.drupal.org/sa-contrib-2026-122


https://www.drupal.org/sa-contrib-2026-123


https://www.drupal.org/sa-contrib-2026-124


https://www.drupal.org/sa-contrib-2026-125


https://www.drupal.org/sa-contrib-2026-126


https://www.drupal.org/sa-contrib-2026-127


https://www.drupal.org/sa-contrib-2026-128


https://www.drupal.org/sa-contrib-2026-129


https://www.drupal.org/sa-contrib-2026-130


https://www.drupal.org/sa-contrib-2026-131


https://www.drupal.org/sa-contrib-2026-132


https://www.drupal.org/sa-contrib-2026-133



Vendor Information


Drupal

https://www.drupal.org/


References


 

https://www.drupal.org/sa-contrib-2026-118

https://www.drupal.org/sa-contrib-2026-119

https://www.drupal.org/sa-contrib-2026-120

https://www.drupal.org/sa-contrib-2026-121

https://www.drupal.org/sa-contrib-2026-122

https://www.drupal.org/sa-contrib-2026-123

https://www.drupal.org/sa-contrib-2026-124

https://www.drupal.org/sa-contrib-2026-125

https://www.drupal.org/sa-contrib-2026-126

https://www.drupal.org/sa-contrib-2026-127

https://www.drupal.org/sa-contrib-2026-128

https://www.drupal.org/sa-contrib-2026-129

https://www.drupal.org/sa-contrib-2026-130

https://www.drupal.org/sa-contrib-2026-131

https://www.drupal.org/sa-contrib-2026-132

https://www.drupal.org/sa-contrib-2026-133




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqivPgACgkQ3jCgcSdc

ys+jTA//QjYo+L0VdcVm2Y2iK54cLrV8yYCk1MYOfsZvoTeCnK6CE/r1C+/ZJke0

JGAzCr9Xs07fkzbRrKEgCO7ZQGOTn6aIlou+h1YC92hSMNW43brr/PQAo6yAYgd4

hPFrflJchoDatezq4qZ5CJYSgcpbuOpWfu2pxCIGg+OqJIWV5ACsmmGhhaJHnKZv

2ZrFt2wbozRMMCUOnsJVFZgLzFJ72Ey2ighnDzUgRDQ114cps5bKDSr6xi9ogrWS

1o0sKsKq5mZHR6r8PZlgJ6V0ebd/5+t/hL7CFlT8LVyDfNv2C1AnWgdwoZJm+yY6

7aClhwrSGqekBqSHgpu8dOWiMfarRvB6Ju5+w/kwGUlLpaBVy/xX8pUmv8MJl/PS

4mDWkTGS8Ab5tIbDZm9wyxy1OE/8PHWRN9xy98qQa9f4m6xmdzu3WVZlLI1T87c7

+3NiHpQqi8bN9f/WRWJgO5lu5nnonHduv/1xScnDPyqL9dDsudgqrxsGYXmGykBZ

X8iCePlmnp82f4Bs4qKC/BkHkR0wY6kEma8Y/Nok9/vxjGX6ugw7wAe3PDWCIROK

lBkcWRTUh/bnWKcA7u8Hlp+PGH61er+gtAhaLXurr8bXVjUpQkdCGSfi52pPHK5Y

B/q8U/MiQzSu2pwwT/gZvVLsM/17zvECDwhfJzXM+tm2ukrpHMg=

=osuU

—–END PGP SIGNATURE—–

Share this article