Robuta

https://www.drupal.org/project/drupal Drupal core | Drupal.org Dec 2, 2025 - Drupal is an open source content management platform supporting a variety of websites ranging from personal weblogs to large community-driven websites. Learn... drupal core https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Theme/10 namespace Drupal\Core\Theme | Drupal API drupal corenamespacethemeapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Entity%21Controller/10 namespace Drupal\Core\Entity\Controller | Drupal API drupal corenamespaceentitycontrollerapi https://www.drupal.org/about/core/policies/maintainers/release-notes Writing release notes for Drupal core releases | Release management | About guide on Drupal.org Jun 3, 2025 - Formatting, content, and process guidelines for release notes of core releases release notesdrupal core https://advisories.gitlab.com/composer/drupal/drupal/CVE-2024-55634/ Drupal core Access bypass | GitLab Advisory Database (GLAD) CVE-2024-55634 Drupal core Access bypass: Drupal's uniqueness checking for certain user fields is inconsistent depending on the database engine and its... drupal coreaccessbypassgitlabadvisory https://www.drupal.org/community-initiatives/previousinactive-initiatives/views-in-drupal-core/views-in-drupal-core-vdc Views in Drupal Core (VDC) | Views in Drupal Core | About guide on Drupal.org Oct 6, 2020 - Views is in Drupal 8 core. At this stage in Drupal 8, most members of initiatives are helping across all initiatives, focusing on criticals drupal coreabout guideviewsvdc https://www.drupal.org/project/issues/drupal?categories=All Issues for Drupal core | Drupal.org drupal coreissues https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Plugin%21Context/10 namespace Drupal\Core\Plugin\Context | Drupal API drupal corenamespaceplugincontextapi https://www.drupal.org/sa-core-2019-012 Drupal core - Critical - Multiple vulnerabilities - SA-CORE-2019-012 | Drupal.org Aug 21, 2022 - The Drupal project uses the third-party library Archive_Tar, which has released a security improvement that is needed to protect some Drupal configurations.... drupal corecriticalmultiplevulnerabilitiessa https://www.drupal.org/sa-core-2021-008 Drupal core - Moderately critical - Access bypass - SA-CORE-2021-008 | Drupal.org Aug 21, 2022 - Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an... drupal corecritical accessmoderatelybypasssa https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Command/11.x namespace Drupal\Core\Command | Drupal API drupal corenamespacecommandapi https://www.drupal.org/node/2281635 \Drupal\Core\Plugin\Context\Context should use a ContextDefinition class instead of arrays... Jul 29, 2014 - Problem/Motivation The Context class currently uses an array to represent its definition. It almost exactly mimics the DataDefinition class, but is not... drupal core https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Utility/10 namespace Drupal\Core\Utility | Drupal API drupal corenamespaceutilityapi https://www.drupal.org/sa-core-2019-004 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-004 | Drupal.org Aug 21, 2022 - Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability. cross site scriptingdrupal coremoderatelycritical https://www.drupal.org/docs/develop/issues/issue-procedures-and-etiquette/core-scope Issue scope guidelines for Drupal core issues | Issue procedures and etiquette | Drupal Wiki guide... Dec 31, 2025 - Guidelines for deciding what belongs in a single Drupal core issue drupal core https://www.drupal.org/node/3089526 jQuery UI source added to Drupal core and deprecated code removed | Drupal.org Oct 19, 2022 - jQuery UI is being phased out of Drupal core, and most libraries were deprecated in 8.8 and moved to contributed modules. jQuery UI Sortable has been replaced... jquery uidrupal core https://advisories.gitlab.com/composer/drupal/drupal/GHSA-j66p-fvp2-fxhj/ Drupal core Arbitrary PHP code execution | GitLab Advisory Database (GLAD) GHSA-j66p-fvp2-fxhj Drupal core Arbitrary PHP code execution: The Drupal project uses the PEAR Archive_Tar library. The PEAR Archive_Tar library has released a... drupal corephp codearbitraryexecutiongitlab https://www.drupal.org/sa-core-2025-008 Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 | Drupal.org Nov 13, 2025 - The core system module handles downloads of private and temporary files. Contrib modules can define additional kinds of files (schemes) that may also be... drupal corecritical informationmoderatelydisclosuresa https://www.drupal.org/sa-core-2025-006 Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 | Drupal.org Nov 13, 2025 - Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget chain"... drupal coremoderatelycriticalgadgetchain https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Http%21Exception/10 namespace Drupal\Core\Http\Exception | Drupal API drupal corenamespacehttpexceptionapi https://advisories.gitlab.com/composer/drupal/drupal/GHSA-5x28-3f32-x523/ Drupal core Access control bypass | GitLab Advisory Database (GLAD) GHSA-5x28-3f32-x523 Drupal core Access control bypass : The Media Library module has a security vulnerability whereby it doesn't sufficiently restrict access... drupal coreaccess controlbypassgitlabadvisory https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Logger/8.9.x namespace Drupal\Core\Logger | Drupal API drupal corenamespaceloggerapi https://advisories.gitlab.com/composer/drupal/core/CVE-2022-25273/ Improper input validation in Drupal core | GitLab Advisory Database (GLAD) CVE-2022-25273 Improper input validation in Drupal core: Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be... input validationdrupal coreimpropergitlabadvisory https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test%21RunTests/10 namespace Drupal\Core\Test\RunTests | Drupal API drupal corenamespacetestapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21File/8.9.x namespace Drupal\Core\File | Drupal API drupal corenamespacefileapi https://advisories.gitlab.com/composer/drupal/core/CVE-2023-31250/ Access bypass in Drupal core | GitLab Advisory Database (GLAD) CVE-2023-31250 Access bypass in Drupal core: The file download facility does not sufficiently sanitize file paths in certain situations. This may result in... drupal coreaccessbypassgitlabadvisory https://www.drupal.org/project/dashboards/issues/3212165 Drupal\Core\Security\UntrustedCallbackException: Render #lazy_builder callbacks must be methods of... May 20, 2021 - Problem/Motivation When adding the "Show rss news" block to the dashboard, an error occurs: Drupal\Core\Security\UntrustedCallbackException: Render... drupal core https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Datetime/8.9.x namespace Drupal\Core\Datetime | Drupal API drupal corenamespacedatetimeapi https://www.drupal.org/project/issues/drupal?categories=All&status=14 Issues for Drupal core | Drupal.org drupal coreissues https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Theme/8.9.x namespace Drupal\Core\Theme | Drupal API drupal corenamespacethemeapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21TypedData%21Plugin%21DataType/9 namespace Drupal\Core\TypedData\Plugin\DataType | Drupal API drupal corenamespaceplugindatatypeapi https://www.drupal.org/sa-core-2026-002 Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 | Drupal.org Apr 15, 2026 - Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site. This so-called "gadget... drupal coremoderatelycriticalgadgetchain https://www.drupal.org/community/contributor-guide/role/drupal-core-leadership-team Drupal Core Leadership Team | Drupal.org core leadership teamdrupal https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Routing/8.9.x namespace Drupal\Core\Routing | Drupal API drupal corenamespaceroutingapi https://advisories.gitlab.com/composer/drupal/drupal/CVE-2024-55638/ Drupal core contains a potential PHP Object Injection vulnerability | GitLab Advisory Database... CVE-2024-55638 Drupal core contains a potential PHP Object Injection vulnerability: Drupal core contains a potential PHP Object Injection vulnerability that... drupal core https://advisories.gitlab.com/composer/drupal/core/CVE-2024-55638/ Drupal core contains a potential PHP Object Injection vulnerability | GitLab Advisory Database... CVE-2024-55638 Drupal core contains a potential PHP Object Injection vulnerability: Drupal core contains a potential PHP Object Injection vulnerability that... drupal core https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Cache/main namespace Drupal\Core\Cache | Drupal API drupal corenamespacecacheapi https://www.drupal.org/community/contributor-guide/role/drupal-core-initiative-coordinator Drupal core initiative coordinator | Drupal.org drupal coreinitiativecoordinator https://www.drupal.org/about/core Drupal Core Development | Drupal.org drupal coredevelopment https://www.drupal.org/node/244637 SA-2008-026 - Drupal core - Access bypass | Drupal.org Mar 10, 2009 - Advisory ID: DRUPAL-SA-2008-026 Project: Drupal core Version: 6.x Date: 2008-April-09 Security risk: Moderately critical Exploitable from: Remote... drupal coresaaccessbypass https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21ParamConverter/10 namespace Drupal\Core\ParamConverter | Drupal API drupal corenamespaceapi https://www.drupal.org/project/drupal/issues/3466719 Drupal core committers meeting 2024-08-05 [#3466719] | Drupal.org Jun 18, 2025 - Issue to capture participation in the core committers monthly meeting in Slack drupal corecommittersmeeting https://www.drupal.org/list-changes/drupal/published?keywords_description=new+experimental+module&to_branch=&version=&created_op=%3E%3D&created%5Bvalue%5D=&created%5Bmin%5D=&created%5Bmax%5D= Change records for Drupal core | Drupal.org change recordsdrupal core https://advisories.gitlab.com/composer/drupal/core/CVE-2025-13080/ Drupal core allows Forceful Browsing | GitLab Advisory Database (GLAD) CVE-2025-13080 Drupal core allows Forceful Browsing: Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful... drupal coreallowsforcefulbrowsinggitlab https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Path/main namespace Drupal\Core\Path | Drupal API drupal corenamespacepathapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Render%21Element/9 namespace Drupal\Core\Render\Element | Drupal API drupal corenamespacerenderelementapi https://www.drupal.org/sa-core-2023-001 Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001 | Drupal.org Nov 22, 2024 - The Media Library module does not properly check entity access in some circumstances. This may result in users with access to edit content seeing metadata... drupal corecritical informationmoderatelydisclosuresa https://www.drupal.org/sa-core-2020-012 Drupal core - Critical - Remote code execution - SA-CORE-2020-012 | Drupal.org Aug 21, 2022 - Update November 18: Documented longer list of dangerous file extensions Drupal core does not properly sanitize certain filenames on uploaded files, which can... remote code executiondrupal corecriticalsa https://advisories.gitlab.com/pkg/composer/drupal/core/GHSA-7f4f-p7mq-p4fv/ https://advisories.gitlab.com/composer/drupal/core/GHSA-7f4f-p7mq-p4fv/ drupal corehttpsadvisoriesgitlabcomposer https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Layout/11.x namespace Drupal\Core\Layout | Drupal API drupal corenamespacelayoutapi https://www.drupal.org/node/3060/qa Drupal core | Drupal.org drupal core https://www.drupal.org/sa-core-2018-002 Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002 | Drupal.org Aug 21, 2022 - A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack... remote code executiondrupal corehighlycritical https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Form/main namespace Drupal\Core\Form | Drupal API drupal corenamespaceformapi https://www.drupal.org/sa-core-2020-009 Drupal core - Critical - Cross-site scripting - SA-CORE-2020-009 | Drupal.org Aug 21, 2022 - Drupal 8 and 9 have a reflected cross-site scripting (XSS) vulnerability under certain circumstances. An attacker could leverage the way that HTML is rendered... cross site scriptingdrupal corecriticalsa https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Database%21Transaction/10 namespace Drupal\Core\Database\Transaction | Drupal API drupal corenamespacedatabasetransactionapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Access/10 namespace Drupal\Core\Access | Drupal API drupal corenamespaceaccessapi https://www.drupal.org/project/issues/drupal?text=&status=Open&priorities=All&categories=All&version=All&component=documentation Issues for Drupal core | Drupal.org drupal coreissues https://www.drupal.org/list-changes/3060/published Change records for Drupal core | Drupal.org change recordsdrupal core https://www.drupal.org/sa-core-2018-006 Drupal Core - Multiple Vulnerabilities - SA-CORE-2018-006 | Drupal.org Oct 28, 2024 - Advisory ID: DRUPAL-SA-CORE-2018-006 Project: Drupal core Version: 7.x, 8.x Date: 2018-October-17 Description Content moderation - Moderately critical - Access... drupal coremultiplevulnerabilitiessa https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Annotation/9 namespace Drupal\Core\Annotation | Drupal API drupal corenamespaceannotationapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Database%21Driver%21mysql/10 namespace Drupal\Core\Database\Driver\mysql | Drupal API drupal corenamespacedatabasedrivermysql https://www.drupal.org/project/drupal/issues/3457744 Drupal core committers team meeting - Dev Days Burgas 2024 [#3457744] | Drupal.org Jun 18, 2025 - Issue to capture participation in the two-day Drupal core committer team meeting, June 24-25 in Burgas (and remotely) before Dev Days. drupal coreteam meetingdev dayscommitters https://www.drupal.org/node/66763 SA-2006-007 - Drupal Core - Revision to DRUPAL-SA-2006-006 | Drupal.org Mar 10, 2009 - Advisory ID: DRUPAL-SA-2006-007 Project: Drupal core and potentially any web application that accepts uploads. Date: 2006-Jun-01 Security risk: highly critical... drupal coresarevision https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test%21HttpClientMiddleware/9 namespace Drupal\Core\Test\HttpClientMiddleware | Drupal API drupal corenamespacetestapi https://packagist.org/packages/drupal/core-assertion drupal/core-assertion - Packagist.org Provides helper functionality for runtime assertions. drupal coreassertionpackagist https://www.drupal.org/sa-core-2022-002 Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002 | Drupal.org Aug 21, 2022 - jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be... cross site scriptingdrupal coremoderatelycritical https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiple Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-004 | Drupal.org Aug 17, 2017 - Drupal 8.3.7 is a maintenance release which contain fixes for security vulnerabilities. Download Drupal 8.3.7 Updating your existing Drupal 8 sites is strongly... drupal coremultiplevulnerabilitiessa https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Plugin/10 namespace Drupal\Core\Plugin | Drupal API drupal corenamespacepluginapi https://advisories.gitlab.com/composer/drupal/core/GHSA-vfgc-c76h-mwh4/ Drupal core Cross-Site Scripting (XSS) vulnerabilities | GitLab Advisory Database (GLAD) GHSA-vfgc-c76h-mwh4 Drupal core Cross-Site Scripting (XSS) vulnerabilities: The Drupal project uses the CKEditor, library for WYSIWYG editing. CKEditor has... cross site scriptingdrupal core https://www.drupal.org/sa-core-2020-010 Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2020-010 | Drupal.org Aug 21, 2022 - Drupal core's built-in CKEditor image caption functionality is vulnerable to XSS. cross site scriptingdrupal coremoderatelycritical https://www.drupal.org/project/drupal/issues/3458405 Drupal core committers meeting 2024-06-11 [#3458405] | Drupal.org Jun 18, 2025 - Issue to capture participation in the core committers monthly meeting in Slack drupal corecommittersmeeting https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21FileTransfer/9 namespace Drupal\Core\FileTransfer | Drupal API drupal corenamespacefiletransferapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21TypedData%21Type/9 namespace Drupal\Core\TypedData\Type | Drupal API drupal corenamespacetypeapi https://advisories.gitlab.com/composer/drupal/core/CVE-2025-13081/ Drupal core allows Object Injection | GitLab Advisory Database (GLAD) CVE-2025-13081 Drupal core allows Object Injection: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal... drupal coreallowsobjectinjectiongitlab https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Locale/11.x namespace Drupal\Core\Locale | Drupal API drupal corenamespacelocaleapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Plugin%21Definition/11.x namespace Drupal\Core\Plugin\Definition | Drupal API drupal corenamespaceplugindefinitionapi https://www.drupal.org/security/core Security advisories for Drupal core | Drupal.org security advisoriesdrupal core https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Recipe/main namespace Drupal\Core\Recipe | Drupal API drupal corenamespacerecipeapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21ProxyClass%21Extension/9 namespace Drupal\Core\ProxyClass\Extension | Drupal API drupal corenamespaceextensionapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Render%21Element/main namespace Drupal\Core\Render\Element | Drupal API drupal corenamespacerenderelementapi https://www.drupal.org/project/drupal/issues/3484404 Drupal\Core\Datetime::dateFormat() does not properly cache results [#3484404] | Drupal.org Nov 13, 2024 - Problem/Motivation I have a page that displays a series of calendar events, where each event has a start and end date. I found that having just a dozen or so... drupal coredoes notdatetimedateformat https://advisories.gitlab.com/composer/drupal/core/CVE-2025-31673/ Drupal Core Vulnerable to Forceful Browsing | GitLab Advisory Database (GLAD) CVE-2025-31673 Drupal Core Vulnerable to Forceful Browsing: Incorrect Authorization vulnerability in Drupal core allows Forceful Browsing.This issue affects... drupal corevulnerableforcefulbrowsinggitlab https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Entity%21Plugin%21Condition%21Deriver/main namespace Drupal\Core\Entity\Plugin\Condition\Deriver | Drupal API drupal corenamespaceentityplugincondition https://www.drupal.org/sa-core-2020-003 Drupal core - Moderately critical - Open Redirect - SA-CORE-2020-003 | Drupal.org Aug 21, 2022 - Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an... drupal coreopen redirectmoderatelycriticalsa https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21TypedData%21Plugin%21DataType/main namespace Drupal\Core\TypedData\Plugin\DataType | Drupal API drupal corenamespaceplugindatatypeapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test/main namespace Drupal\Core\Test | Drupal API drupal corenamespacetestapi https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Security/10 namespace Drupal\Core\Security | Drupal API drupal corenamespacesecurityapi https://www.drupal.org/sa-core-2026-001 Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 | Drupal.org Apr 15, 2026 - Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which which can lead to a cross-site scripting... cross site scriptingdrupal corecriticalsa https://dev.to/jcandan/full-width-drupal-core-remote-video-with-youtube-parameters-12kf Full-width, Drupal core Remote Video with YouTube parameters - DEV Community Drupal core supplies us a Remote Video media type. To display Media items of this type in a block,... Tagged with ai, learning, career. full widthdrupal coreremote video https://www.drupal.org/sa-core-2019-003 Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003 | Drupal.org Aug 21, 2022 - Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases. A site is only affected by... remote code executiondrupal corehighlycritical https://api.drupal.org/api/drupal/namespace/Drupal%21Core%21Test/10 namespace Drupal\Core\Test | Drupal API drupal corenamespacetestapi https://www.drupal.org/about/core/policies/core-change-policies/experimental/policy-and-list Experimental modules and themes in Drupal core | Experimental modules and themes | About guide on... Apr 14, 2026 - Introduction to experimental modules and themes, and a list of them currently in development modules and themesdrupal coreabout guideexperimental https://advisories.gitlab.com/composer/drupal/core-recommended/CVE-2024-55637/ Drupal core contains a potential PHP Object Injection vulnerability | GitLab Advisory Database... CVE-2024-55637 Drupal core contains a potential PHP Object Injection vulnerability: Drupal core contains a potential PHP Object Injection vulnerability that... drupal core https://www.drupal.org/sa-core-2020-002 Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002 | Drupal.org Aug 21, 2022 - The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the... cross site scriptingdrupal coremoderatelycritical https://www.drupal.org/psa-2018-002 Drupal Core - Highly Critical - Public Service announcement - PSA-2018-002 | Drupal.org Sep 16, 2019 - Project: Drupal core Version: 7.x, 8.x Description This Public Service Announcement is a follow-up to SA-CORE-2018-002 - Drupal core - RCE. This is not an... public service announcementdrupal corehighlycritical https://groups.drupal.org/node/430073 This month in Drupal Core (June 25, 2014) | Drupal Groups this month indrupal corejunegroups https://packagist.org/packages/drupal/core-php-storage drupal/core-php-storage - Packagist.org drupal corephpstoragepackagist https://advisories.gitlab.com/composer/drupal/core/CVE-2024-11942/ Drupal core vulnerable to improper error handling | GitLab Advisory Database (GLAD) CVE-2024-11942 Drupal core vulnerable to improper error handling: Under certain uncommon site configurations, a bug in the CKEditor 5 module can cause some... drupal coreerror handlingvulnerableimproper https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-04-19/drupal-core-critical-access-bypass Drupal Core - Critical - Access Bypass - SA-CORE-2017-002 | Drupal.org Apr 21, 2017 - Advisory ID: DRUPAL-SA-CORE-2017-002 Project: Drupal core Version: 8.x Date: 2017-April-19 CVEID: CVE-2017-6919 Security risk: 17/25 ( Critical)... drupal corecritical accessbypasssa https://advisories.gitlab.com/composer/drupal/drupal/GHSA-jf8c-36vw-98x4/ Drupal core Remote Code Execution | GitLab Advisory Database (GLAD) GHSA-jf8c-36vw-98x4 Drupal core Remote Code Execution: In Drupal core, when sending email some variables were not being sanitized for shell arguments in... remote code executiondrupal coregitlabadvisorydatabase