This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

D7ES PSA relating to SA-CORE-2025-002 impacting Views Bulk Operations (VBO)

Date
SA-CORE-2025-002 communicates a security issue introduced in Drupal 8+. This functionality in modern Drupal was heavily inspired by Views Bulk Operations, which exposes core Actions to be performed against nodes (and other entities). While it does not have the concept of permissions around Actions like in Drupal 8+, Views Bulk Operations (VBO) provides an actions_permissions sub-module. As a mitigation technique, this sub-module should be enabled and configured on Views that expose bulk operations.

General Data Protection Regulation - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-018

Date
Severity
Moderately Critical
Affected versions
7.x-1.0-alpha12
The GDPR Task submodule enables you to create GDPR tasks. The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when creating tasks.

SpamSpan filter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-016

Date
Severity
Moderately Critical
Affected versions
7.x-1.4
This module enables your site to obfuscate Email addresses and prevent spambots to collect them. The module doesn't sanitize HTML data attributes when an email address link is transformed to separate span HTML elements and then transformed back by JavaScript leading to a Cross Site Scripting (XSS) vulnerability.

Webform Multiple File Upload - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.7
The webform_multifile module allows user to upload multiple files on a webform. This vulnerability was originally patched by D7Security Group. This is a public release of the port of that patch, provided to Tag1 D7ES customers.

Google Tag - Moderately critical - Cross Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
< 7.x-2.3
This module enables you to integrate the site with the Google Tag Manager (GTM) application. This vulnerability was originally reported and remediated for modern versions of Drupal in https://www.drupal.org/sa-contrib-2025-011. This security advisory is a public release addressing the vulnerability for Drupal 7, as provided to Tag1 D7ES customers.

Coffee - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
≤7.x-2.3
The Coffee module helps you to navigate through the Drupal admin faster, inspired by Alfred and Spotlight (OS X). This vulnerability was originally patched by D7Security Group. This is a public release of the port of that patch, provided to Tag1 D7ES customers.