This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

Popup - Moderately Critical - Cross-Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-1.5
The Popup module doesn't protect several administrative menu callbacks from cross-site request forgery (CSRF), allowing popup format and description configuration to be changed when an authenticated administrator visits an attacker controlled page.

Popup - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.5
The Popup module exposes an anonymous AHAH callback that renders the body of the targeted content without re-checking the current user's access, allowing an anonymous visitor to retrieve content they should not be able to see, such as an unpublished node.

Brightcove Video Connect - Less Critical - Unrestricted File Upload

Date
Severity
Less Critical
Affected versions
<7.x-6.7
The video upload form accepts poster and thumbnail images using extension based validation only, so a privileged user can store a non-image file bearing an image extension at a public URL.

Feedback Collect - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.9
The Feedback Collect module stores the feedback origin value submitted with each feedback node and later prints it without sanitization in the submitted feedback administration listing and on the feedback node view, allowing a user who can submit feedback to inject arbitrary JavaScript that executes in the browser of any user who views the submitted feedback.

Dynamic Background - Moderately Critical - Cross Site Scripting (Stored)

Date
Severity
Moderately Critical
Affected versions
<7.x-1.12, <7.x-2.1
The background image upload form validates uploaded files by extension only, allowing a user to save a non-image file containing an HTML/JavaScript payload to the public files directory where it can be served back to other users.

Calendar - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-3.7
The Calendar module outputs taxonomy term names and OG group names directly into HTML `title` attributes without sanitization, allowing a user with term or group management permissions to inject arbitrary JavaScript executed in the browser of any visitor viewing a calendar with stripe coloring enabled.

Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070

Date
Severity
Moderately Critical
Affected versions
<7.x-1.4
When login is disabled with an optional access key, the module places no rate limit on attempts to supply that key in the URL, allowing an unauthenticated attacker to guess it through unlimited automated requests and re-enable the login form.