Blog
FAQ
Discussions
Search
Projects, issues, users, and merge requests.
Project ID, name, and description.
User nickname, name, and org.
Issue ID, title, and summary.
Merge request titles.
Contrib
.social
Feed
Live feed
Builds
Live builds
Core
Tags
Tags and Initiatives
#Needs security review
Open on Drupal.org →
⚡️ Live updates
comments, jobs, and issues, tagged with
#Needs security review
will update issues and activities on this page.
Issues
🐛
\Drupal\Core\Security\PharExtensionInterceptor is incompatible with GeoIP and other libraries that use phar aliases or Phar::mapPhar()
Needs work
Drupal core
10.1 —
bootstrap system
Created
over 6 years ago
🇺🇸
United States
samuel.mortenson
7 days ago
📌
[policy, no patch] Secondary subdomain for viewing oEmbed content is confusing and pointless
Active
Drupal core
10.1 —
media system
Created
about 4 years ago
🇺🇸
United States
phenaproxima
12 days ago
📌
[1.0.x] JSON to Content Type Builder
Active
JSON to Content Type Builder
1.0
Created
22 days ago
guri221
22 days ago
🐛
Use email verification when changing user email addresses
Needs work
Drupal core
10.1 —
user.module
Created
almost 19 years ago
🇬🇧
United Kingdom
AjK
about 1 month ago
📌
Don't automatically set a cookie domain
Needs review
Drupal core
10.1 —
base system
Created
over 7 years ago
🇬🇧
United Kingdom
alexpott
about 1 month ago
📌
Check for common words in password strength indicators
Needs work
Drupal core
11.0 —
user.module
Created
over 13 years ago
🇺🇸
United States
webkenny
about 1 month ago
🐛
Url only outputs the last value of a query parameter
Needs work
Drupal core
10.1 —
routing system
Created
over 6 years ago
🇵🇱
Poland
blazey
2 months ago
🐛
Allow password reset on account w username matching another email. Prevent registrations which match another account
Needs review
Drupal core
10.1 —
user.module
Created
over 13 years ago
🇺🇸
United States
hefox
2 months ago
📌
[1.0.x] Video Embed ChampDS
Active
Drupal.org security advisory coverage applications
Created
3 months ago
🇮🇳
India
pmkanse
3 months ago
📌
[1.0.x]Paragraph Locator
Active
Drupal.org security advisory coverage applications
Created
about 1 year ago
🇨🇦
Canada
deepak5423
3 months ago
📌
Possible security issue for the voting route
Active
Like & Dislike
2.0
Created
4 months ago
🇺🇦
Ukraine
HitchShock
4 months ago
📌
Do not use the .php extension in mtime protected storage to work around bogus PHP extensions
Needs work
Drupal core
10.1 —
base system
Created
about 5 years ago
ayushst
4 months ago
🐛
ValidReferenceConstraintValidator should not try to enforce data integrity on pre-existing references
Needs review
Drupal core
10.1 —
entity_reference.module
Created
about 7 years ago
🇮🇳
India
nghai
4 months ago
🐛
Should "iFrame domain" also set "X-Frame-Options" header
Active
Drupal core
11.0 —
media system
Created
almost 6 years ago
🇩🇰
Denmark
osman
5 months ago
📌
GET forms MUST NOT have CSRF tokens
Needs work
Drupal core
11.0 —
forms system
Created
almost 10 years ago
🇧🇪
Belgium
wim leers
5 months ago
📌
[1.0.x] Domain Access Webform
Active
Drupal.org security advisory coverage applications
Created
about 1 year ago
ajay-mallah
5 months ago
🐛
User email should not be case sensitive
Postponed
Drupal core
10.1 —
user.module
Created
about 10 years ago
tvn
5 months ago
✨
Create a global "kill switch" for Package Manager
Needs review
Automatic Updates
3.0
Created
over 3 years ago
🇺🇸
United States
phenaproxima
6 months ago
📌
Security review for 8.x-1.0
Active
Resource Hints
1.0
Created
over 8 years ago
🇺🇸
United States
bighappyface
7 months ago
🐛
Dots in query parameter names converted to underscores
Needs work
Drupal core
9.5 —
menu system
Created
about 7 years ago
🇺🇸
United States
awolfey
9 months ago
✨
Allow to change upload formats for managed_file
Needs work
Menu Link Attributes
1.0
Created
about 2 years ago
🇺🇦
Ukraine
NotifyOne
11 months ago
🌱
Consider using phpstorage for update module
Closed: outdated
Drupal core
11.0 —
update.module
Created
about 9 years ago
🇬🇧
United Kingdom
catch
about 1 year ago
🐛
User must be logged-in to use the cancel account link that is emailed
Needs work
Drupal core
11.0 —
user.module
Created
over 8 years ago
🇬🇧
United Kingdom
xiwar
about 1 year ago
✨
Allow the use of symlinks within the files directory.
Needs work
Drupal core
11.0 —
file system
Created
over 14 years ago
🇺🇸
United States
tekante
about 1 year ago
📌
Password reset form error makes no sense when the account is locked
Needs work
Drupal core
11.0 —
user system
Created
over 2 years ago
🇨🇳
China
xiukun.zhou
about 1 year ago
🐛
"Restrict images to this site" restricts images that, by definition, *are* on this site.
Needs work
Drupal core
11.0 —
filter.module
Created
almost 7 years ago
🇺🇸
United States
ben coleman
over 1 year ago
🐛
Avoid overwriting .htaccess changes during scaffolding > security problem
Needs work
Drupal core
11.0 —
composer
Created
over 5 years ago
🇺🇸
United States
becw
over 1 year ago
📌
[PP-1] Add security checking for Symfony Mailer transports
Postponed
Drupal core
11.0 —
mail system
Created
almost 2 years ago
🇬🇧
United Kingdom
adamps
over 1 year ago
✨
Allow README.md to optionally render as the project page
Fixed
Drupal.org customizations
3.0
Created
about 13 years ago
🇺🇸
United States
cashwilliams
almost 2 years ago
🐛
Stream wrappers don't decode url encoded URIs
Needs work
Drupal core
9.5 —
file system
Created
over 13 years ago
🇨🇭
Switzerland
berdir
almost 2 years ago
💬
Apply for Drupal Security Advisory Coverage
Closed: duplicate
Advanced Link Attributes
2.5
Created
about 2 years ago
🇨🇦
Canada
aastrong
almost 2 years ago
📌
Please opt into security advisory coverage
Closed: duplicate
Widen Collective
1.0
Created
almost 8 years ago
🇺🇸
United States
john.oltman
almost 2 years ago
🐛
text_summary() returns a plain string, even if passed a MarkupInterface object
Needs work
Drupal core
11.0 —
text.module
Created
about 6 years ago
🇺🇸
United States
effulgentsia
about 2 years ago
📌
Deprecate the "Full HTML" text format in Standard and Umami in favor of a "content editor HTML" for content editor roles
Active
Drupal core
11.0 —
filter.module
Created
over 5 years ago
🇦🇺
Australia
larowlan
about 2 years ago
✨
Allow selection of which folder a file is to on the file/add form
Needs review
File Entity (fieldable files)
2.0
Created
about 12 years ago
🇺🇸
United States
dave reid
about 2 years ago
📌
Add YAML support to serialization module
Needs work
Drupal core
10.1 —
serialization.module
Created
over 12 years ago
🇬🇧
United Kingdom
damiankloip
over 2 years ago
🐛
make x-frame-options configurable
Postponed
Drupal core
10.1 —
request processing system
Created
over 9 years ago
🇨🇭
Switzerland
yobottehg
over 2 years ago
🐛
The XSS filter should allow more HTML entities
Needs work
Drupal core
10.1 —
base system
Created
almost 6 years ago
🇨🇿
Czech Republic
martin_klima
over 2 years ago
🐛
MapItem unserialize function in setValue method should allow TranslatableMarkup class
Needs work
Drupal core
10.1 —
field system
Created
over 6 years ago
🇭🇷
Croatia
xSDx
over 2 years ago
🐛
Xss::filter() does not handle HTML tags inside attribute values
Closed: duplicate
Drupal core
10.1 —
filter.module
Created
almost 4 years ago
🇬🇧
United Kingdom
longwave
over 2 years ago
✨
Drupal 10 compatibility
Fixed
jQuery UI
1.0
Created
about 3 years ago
🇺🇸
United States
effulgentsia
over 2 years ago
🐛
htmlspecialchars() expects parameter 1 to be string, array given
Needs work
Drupal core
9.5 —
markup
Created
about 6 years ago
🇧🇬
Bulgaria
Plamen.Penev
over 2 years ago
Activities
No activities found.
contrib
.social
Blog
FAQ
Discussions
Production build 0.71.5
2024