This page displays all public Tag1 D7ES Security Advisories. Check out our Announcements page for all updates.

You can filter this list by project or subscribe to the RSS feed.

 

File (Field) Paths - Moderately Critical - File Path Manipulation

Date
Severity
Moderately Critical
Affected versions
<7.x-1.3
The File (Field) Paths module contained a file path manipulation vulnerability where file objects maintained inconsistent URI state after file move operations, potentially leading to file access issues and data corruption.

EU Cookie Compliance (GDPR Compliance) - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-072

Date
Severity
Moderately Critical
Affected versions
<7.x-1.45
The EU Cookie Compliance module doesn't sufficiently verify whether "disabled JavaScript" entries are valid or correspond to actual scripts on the page.

Stage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035

Date
Severity
Moderately Critical
Affected versions
<7.x-1.11
Stage File Proxy is a solution for transferring production files to a development server on demand. The module doesn't sufficiently validate the existence of remote files prior to attempting to download and create them.

Commerce Paybox - Moderately Critical - Payment bypass vulnerability

Date
Severity
Moderately Critical
Affected versions
<7.x-1.6
The Commerce Paybox module integrates with Verifone e-commerce for accepting online payments. A payment bypass vulnerability could be exploited to mark a payment as done and flag an order as completed, without the user actually entering a credit card number.