Blog
FAQ
Discussions
Search
Projects, issues, users, and merge requests.
Project ID, name, and description.
User nickname, name, and org.
Issue ID, title, and summary.
Merge request titles.
Contrib
.social
Feed
Live feed
Builds
Live builds
Core
Tags
Tags and Initiatives
#Needs security review
Open on Drupal.org β
β‘οΈ Live updates
comments, jobs, and issues, tagged with
#Needs security review
will update issues and activities on this page.
Issues
π
The Content overview page filters out unpublished nodes when a node access module is enabled
Needs work
Drupal core
11.0 β
node system
Created
6 months ago
ππΊ
Hungary
mxr576
14 days ago
π
[policy, no patch] Secondary subdomain for viewing oEmbed content is confusing and pointless
Active
Drupal core
11.0 β
media system
Created
over 3 years ago
πΊπΈ
United States
phenaproxima
23 days ago
π±
Security review of secure signing components for package manager
Needs review
Drupal core
11.0 β
update.module
Created
over 1 year ago
πΊπΈ
United States
hestenet
29 days ago
π
Dots in query parameter names converted to underscores
Needs work
Drupal core
9.5 β
menu system
Created
over 6 years ago
πΊπΈ
United States
awolfey
about 1 month ago
π
ValidReferenceConstraintValidator should not try to enforce data integrity on pre-existing references
Needs work
Drupal core
11.0 β
entity_reference.module
Created
over 6 years ago
π©πͺ
Germany
nghai
about 1 month ago
π
Don't automatically set a cookie domain
Needs review
Drupal core
10.1 β
base system
Created
almost 7 years ago
π¬π§
United Kingdom
alexpott
about 2 months ago
β¨
Allow to change upload formats for managed_file
Needs work
Menu Link Attributes
1.0
Created
over 1 year ago
πΊπ¦
Ukraine
NotifyOne
3 months ago
π
Security review for 8.x-1.0
Active
Resource Hints
1.0
Created
almost 8 years ago
πΊπΈ
United States
bighappyface
4 months ago
π±
Consider using phpstorage for update module
Closed: outdated
Drupal core
11.0 β
update.module
Created
over 8 years ago
π¬π§
United Kingdom
catch
5 months ago
π
User must be logged-in to use the cancel account link that is emailed
Needs work
Drupal core
11.0 β
user.module
Created
almost 8 years ago
π¬π§
United Kingdom
xiwar
6 months ago
β¨
Allow the use of symlinks within the files directory.
Needs work
Drupal core
11.0 β
file system
Created
almost 14 years ago
πΊπΈ
United States
tekante
7 months ago
π
Should "iFrame domain" also set "X-Frame-Options" header
Needs work
Drupal core
11.0 β
media system
Created
over 5 years ago
πΊπΈ
United States
osman
7 months ago
π
Password reset form error makes no sense when the account is locked
Needs work
Drupal core
11.0 β
user system
Created
over 1 year ago
π¨π³
China
xiukun.zhou
7 months ago
π
Url only outputs the last value of a query parameter
Needs work
Drupal core
11.0 β
routing system
Created
over 5 years ago
π΅π±
Poland
blazey
7 months ago
π
"Restrict images to this site" restricts images that, by definition, *are* on this site.
Needs work
Drupal core
11.0 β
filter.module
Created
about 6 years ago
πΊπΈ
United States
Ben Coleman
8 months ago
π
Avoid overwriting .htaccess changes during scaffolding > security problem
Needs work
Drupal core
11.0 β
composer
Created
about 5 years ago
πΊπΈ
United States
becw
8 months ago
π
[PP-1] Add security checking for Symfony Mailer transports
Postponed
Drupal core
11.0 β
mail system
Created
about 1 year ago
π¬π§
United Kingdom
adamps
about 1 year ago
β¨
Allow README.md to optionally render as the project page
Fixed
Drupal.org customizations
3.0
Created
over 12 years ago
πΊπΈ
United States
cashwilliams
about 1 year ago
π
Stream wrappers don't decode url encoded URIs
Needs work
Drupal core
9.5 β
file system
Created
over 12 years ago
π¨π
Switzerland
berdir
about 1 year ago
π¬
Apply for Drupal Security Advisory Coverage
Closed: duplicate
Advanced Link Attributes
2.5
Created
over 1 year ago
π¨π¦
Canada
aastrong
about 1 year ago
π
Please opt into security advisory coverage
Closed: duplicate
Widen Collective
1.0
Created
about 7 years ago
πΊπΈ
United States
john.oltman
over 1 year ago
π
text_summary() returns a plain string, even if passed a MarkupInterface object
Needs work
Drupal core
11.0 β
text.module
Created
over 5 years ago
πΊπΈ
United States
effulgentsia
over 1 year ago
π
Allow password reset on account with the username matching another email; prevent registrations that match another account
Needs work
Drupal core
11.0 β
user.module
Created
almost 13 years ago
πΊπΈ
United States
hefox
over 1 year ago
π
Deprecate the "Full HTML" text format in Standard and Umami in favor of a "content editor HTML" for content editor roles
Active
Drupal core
11.0 β
filter.module
Created
almost 5 years ago
π¦πΊ
Australia
larowlan
over 1 year ago
β¨
Create a global "kill switch" for Package Manager?
Active
Automatic Updates
3.0
Created
over 2 years ago
πΊπΈ
United States
phenaproxima
over 1 year ago
β¨
Allow selection of which folder a file is to on the file/add form
Needs review
File Entity (fieldable files)
2.0
Created
over 11 years ago
πΊπΈ
United States
dave reid
over 1 year ago
π
Add YAML support to serialization module
Needs work
Drupal core
10.1 β
serialization.module
Created
almost 12 years ago
π¬π§
United Kingdom
damiankloip
almost 2 years ago
π
Do not use the .php extension in mtime protected storage to work around bogus PHP extensions
Postponed: needs info
Drupal core
10.1 β
base system
Created
over 4 years ago
ayushst
almost 2 years ago
π
make x-frame-options configurable
Postponed
Drupal core
10.1 β
request processing system
Created
almost 9 years ago
π¨π
Switzerland
yobottehg
almost 2 years ago
π
The XSS filter should allow more HTML entities
Needs work
Drupal core
10.1 β
base system
Created
about 5 years ago
π¨πΏ
Czech Republic
martin_klima
almost 2 years ago
π
MapItem unserialize function in setValue method should allow TranslatableMarkup class
Needs work
Drupal core
10.1 β
field system
Created
over 5 years ago
ππ·
Croatia
xSDx
almost 2 years ago
π
Xss::filter() does not handle HTML tags inside attribute values
Closed: duplicate
Drupal core
10.1 β
filter.module
Created
over 3 years ago
π¬π§
United Kingdom
longwave
almost 2 years ago
β¨
Drupal 10 compatibility
Fixed
jQuery UI
1.0
Created
over 2 years ago
πΊπΈ
United States
effulgentsia
almost 2 years ago
π
\Drupal\Core\Security\PharExtensionInterceptor is incompatible with GeoIP and other libraries that use phar aliases or Phar::mapPhar()
Needs work
Drupal core
10.1 β
bootstrap system
Created
almost 6 years ago
πΊπΈ
United States
samuel.mortenson
almost 2 years ago
π
User email should not be case sensitive
Postponed
Drupal core
10.1 β
user.module
Created
over 9 years ago
tvn
almost 2 years ago
π
htmlspecialchars() expects parameter 1 to be string, array given
Needs work
Drupal core
9.5 β
markup
Created
over 5 years ago
π§π¬
Bulgaria
Plamen.Penev
over 1 year ago
Activities
No activities found.
contrib
.social
Blog
FAQ
Discussions
Production build 0.71.5
2024