Skip to main content

Drupal News

News is provide by the latest from the Drupal Community and the latest developments happening around the world.

Matt Glaman: Lenient Composer Plugin officially replaces lenient packages endpoint

20 Nov 2024

Well, it's official. My Drupal Lenient Composer Plugin has allowed the lenient Composer repository endpoint on Drupal.org to be sunset and removed. I created the mglaman/composer-drupal-lenient repository two years ago at DrupalCon Portland. It is pretty wild how much it has been adopted in just...

Security advisories: Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008

20 Nov 2024

Project: Drupal coreDate: 2024-November-20Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Gadget chainAffected versions: >= 8.0.0 < 10.2.11 || >= 10.3.0 < 10.3.9Description: Drupal core...

Security advisories: Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007

20 Nov 2024

Project: Drupal coreDate: 2024-November-20Security risk: Moderately critical 14 ∕ 25 AC:Complex/A:Admin/CI:All/II:All/E:Theoretical/TD:UncommonVulnerability: Gadget chainAffected versions: >= 8.0.0 < 10.2.11 || >= 10.3.0 < 10.3.9 || >= 11.0.0 < 11.0....

Security advisories: Drupal core - Less critical - Gadget chain - SA-CORE-2024-006

20 Nov 2024

Project: Drupal coreDate: 2024-November-20Security risk: Less critical 8 ∕ 25 AC:Complex/A:User/CI:None/II:Some/E:Theoretical/TD:UncommonVulnerability: Gadget chainAffected versions: >= 8.0.0 < 10.2.11 || >= 10.3.0 < 10.3.9 || >= 11.0.0 < 11.0.8Description...

Security advisories: Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005

20 Nov 2024

Project: Drupal coreDate: 2024-November-20Security risk: Critical 17 ∕ 25 AC:None/A:None/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingDescription: Drupal 7 core's Overlay module doesn't safely handle user input, leading to reflected cross-site...

Security advisories: Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004

20 Nov 2024

Project: Drupal coreDate: 2024-November-20Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:User/CI:None/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: >= 8.0.0 < 10.2.11 || >= 10.3.0 < 10.3.9 || >= 11.0.0 < 11.0....

Security advisories: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003

20 Nov 2024

Project: Drupal coreDate: 2024-November-20Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingAffected versions: >= 8.8.0 < 10.2.11 || >= 10.3.0 < 10.3.9 || >= 11.0.0 < 11.0....

Drupal Association blog: Celebrating Success: DrupalCon Barcelona 2024 Event Impact Recap

19 Nov 2024

Welcome to the Event Impact Recap of DrupalCon Barcelona 2024. This year’s conference not only showcased the vibrant spirit of our global network but also highlighted the achievements and successes that emerged from this remarkable gathering. As we look forward to upcoming events in Singapore and...

Specbee: Your essential guide to Multilingual SEO and Hreflang (and how Drupal makes it easier)

19 Nov 2024

Multilingual websites can attract a wider audience! Read this blog to strengthen your technical knowledge about multilingual SEO and the impact of hreflang tags.

Nonprofit Drupal posts: November Drupal for Nonprofits Chat

18 Nov 2024

Join us THURSDAY, November 21 at 1pm ET / 10am PT, for our regularly scheduled call to chat about all things Drupal and nonprofits. (Convert to your local time zone.) We don't have anything specific on the agenda this month, so we'll have plenty of time to discuss anything that's on our minds at...

Pages

Top