This page displays all public Tag1 D7ES Security Advisories. Check out our Announcements page for all updates.

You can filter this list by project or subscribe to the RSS feed.

 

Filebrowser - Moderately Critical - Risk of data exposure

Date
Severity
Moderately Critical
Affected versions
All Drupal 7 versions are affected
The Filebrowser module allows users to browse a list of files in specific directories. This module and its directory listing node type should only be used by users with elevated user access.

Commerce Paybox - Moderately Critical - Payment bypass vulnerability

Date
Severity
Moderately Critical
Affected versions
<7.x-1.6
The Commerce Paybox module integrates with Verifone e-commerce for accepting online payments. A payment bypass vulnerability could be exploited to mark a payment as done and flag an order as completed, without the user actually entering a credit card number.

Stage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035

Date
Severity
Moderately Critical
Affected versions
<7.x-1.11
Stage File Proxy is a solution for transferring production files to a development server on demand. The module doesn't sufficiently validate the existence of remote files prior to attempting to download and create them.

Colorbox - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-041

Date
Severity
Moderately Critical
Affected versions
<7.x-2.20
The Colorbox module allows images, iframed, or inline content to be displayed in a modal above the current page. It doesn't sufficiently sanitize data attributes before opening modals.

Flag - Moderately Critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-011

Date
Severity
Moderately Critical
Affected versions
<7.x-3.10
The module doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow specially crafted HTML to result in Cross Site Scripting.

Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-028

Date
Severity
Moderately Critical
Affected versions
< 7.x-1.2
The Access code module allows site visitors to log in using an access code instead of entering username and password. The module doesn't sufficiently protect against brute force attacks to guess a user's access code.

Link - Moderately critical - Cross Site Scripting - SA-CORE-2025-004

Date
Severity
Moderately Critical
Affected versions
< 7.x-1.13
The link module provides a standard custom content field for links. This release is a backport of SA-CORE-2025-004, with the addition of a hook_update to register the new sanitization PHP class in Drupal 7's class registry.