This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

Coffee - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
≤7.x-2.3
The Coffee module helps you to navigate through the Drupal admin faster, inspired by Alfred and Spotlight (OS X). This vulnerability was originally patched by D7Security Group. This is a public release of the port of that patch, provided to Tag1 D7ES customers.

Webform Multiple File Upload - Critical - Cross Site Scripting - D7SECURITY-SA-CONTRIB-2025-001

Date
Severity
Critical
Affected versions
<7.x-1.7
The Webform Multiple File Upload module allows users to upload multiple files on a Webform. The module doesn't sufficiently escape filenames when displaying them, thereby exposing an XSS vulnerability. This vulnerability is mitigated by the fact that an attacker must have access to a Webform that allows multiple file uploads.