
[CIVN-2026-0447] Multiple Vulnerabilities in Drupal Modules
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Drupal Modules
Original Issue Date:September 09, 2026
Severity Rating: HIGH
Software Affected
Webform Submissions Delete module prior to versions 1.2.0
Unpublished Node Permissions module prior to versions 1.8.0
PhotoSwipe – Responsive JavaScript Modal Image Gallery module versions prior to 5.0.9
Monobank payment API module versions prior to 1.0.3
Media Library Importer module versions prior to 2.1.6
Mailer Plus Log module versions prior to 1.2.7
Jsonapi Role Access module versions prior to 2.0.2
Islandora versions module versions prior to 2.19.0
Email Verification / SMS Verification / OTP Verification module versions prior to 2.4.0
Component blocks module versions prior to 1.2.7
Calculate Working Days module versions prior to 2.0.3
AI translate module versions prior to 1.3.2
AI translate module versions from versions 1.4.0 through 1.4.1
AI (Artificial Intelligence) module versions prior to 1.3.13
AI (Artificial Intelligence) module versions from 1.4.0 through 1.4.8
Advanced Search module versions prior to 2.4.5
Overview
Multiple vulnerabilities have been reported in various contributed modules of Drupal, which could allow an attacker to bypass access controls, disclose sensitive information, execute malicious scripts, manipulate application data, or compromise user accounts.
Target Audience:
Individuals and end-user organizations using Drupal Modules.
Risk Assessment:
High risk of unauthorized access, sensitive information disclosure, malicious script execution, and account compromise..
Impact Assessment:
Potential compromise of the confidentiality, integrity, and availability of affected Drupal websites.
Description
Drupal is an open-source content management system (CMS) used to build, manage, and publish websites and digital applications. Drupal modules are essential extensions that enhance Drupals core functionality by adding features such as content management, user authentication, search, APIs, security controls, and third-party integrations.
These vulnerabilities exist due to improper access controls, inadequate input validation, and insufficient authorization checks. An attacker could exploit these vulnerabilities by executing crafted requests or malicious input.
Successful exploitation could result in unauthorized access, sensitive information disclosure, cross site scripting, data manipulation, or account compromise.
Solution
Upgrade to the latest versions as mentioned in the advisory:
https://www.drupal.org/sa-contrib-2026-118
https://www.drupal.org/sa-contrib-2026-119
https://www.drupal.org/sa-contrib-2026-120
https://www.drupal.org/sa-contrib-2026-121
https://www.drupal.org/sa-contrib-2026-122
https://www.drupal.org/sa-contrib-2026-123
https://www.drupal.org/sa-contrib-2026-124
https://www.drupal.org/sa-contrib-2026-125
https://www.drupal.org/sa-contrib-2026-126
https://www.drupal.org/sa-contrib-2026-127
https://www.drupal.org/sa-contrib-2026-128
https://www.drupal.org/sa-contrib-2026-129
https://www.drupal.org/sa-contrib-2026-130
https://www.drupal.org/sa-contrib-2026-131
https://www.drupal.org/sa-contrib-2026-132
https://www.drupal.org/sa-contrib-2026-133
Vendor Information
Drupal
https://www.drupal.org/
References
https://www.drupal.org/sa-contrib-2026-118
https://www.drupal.org/sa-contrib-2026-119
https://www.drupal.org/sa-contrib-2026-120
https://www.drupal.org/sa-contrib-2026-121
https://www.drupal.org/sa-contrib-2026-122
https://www.drupal.org/sa-contrib-2026-123
https://www.drupal.org/sa-contrib-2026-124
https://www.drupal.org/sa-contrib-2026-125
https://www.drupal.org/sa-contrib-2026-126
https://www.drupal.org/sa-contrib-2026-127
https://www.drupal.org/sa-contrib-2026-128
https://www.drupal.org/sa-contrib-2026-129
https://www.drupal.org/sa-contrib-2026-130
https://www.drupal.org/sa-contrib-2026-131
https://www.drupal.org/sa-contrib-2026-132
https://www.drupal.org/sa-contrib-2026-133
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqivPgACgkQ3jCgcSdc
ys+jTA//QjYo+L0VdcVm2Y2iK54cLrV8yYCk1MYOfsZvoTeCnK6CE/r1C+/ZJke0
JGAzCr9Xs07fkzbRrKEgCO7ZQGOTn6aIlou+h1YC92hSMNW43brr/PQAo6yAYgd4
hPFrflJchoDatezq4qZ5CJYSgcpbuOpWfu2pxCIGg+OqJIWV5ACsmmGhhaJHnKZv
2ZrFt2wbozRMMCUOnsJVFZgLzFJ72Ey2ighnDzUgRDQ114cps5bKDSr6xi9ogrWS
1o0sKsKq5mZHR6r8PZlgJ6V0ebd/5+t/hL7CFlT8LVyDfNv2C1AnWgdwoZJm+yY6
7aClhwrSGqekBqSHgpu8dOWiMfarRvB6Ju5+w/kwGUlLpaBVy/xX8pUmv8MJl/PS
4mDWkTGS8Ab5tIbDZm9wyxy1OE/8PHWRN9xy98qQa9f4m6xmdzu3WVZlLI1T87c7
+3NiHpQqi8bN9f/WRWJgO5lu5nnonHduv/1xScnDPyqL9dDsudgqrxsGYXmGykBZ
X8iCePlmnp82f4Bs4qKC/BkHkR0wY6kEma8Y/Nok9/vxjGX6ugw7wAe3PDWCIROK
lBkcWRTUh/bnWKcA7u8Hlp+PGH61er+gtAhaLXurr8bXVjUpQkdCGSfi52pPHK5Y
B/q8U/MiQzSu2pwwT/gZvVLsM/17zvECDwhfJzXM+tm2ukrpHMg=
=osuU
—–END PGP SIGNATURE—–


