Drupal Aid

Drupal Aid

Share

Drupal Support and Maintenance Services. We love Drupal and provide Unlimited support, maintenance, Drupal Support and Maintenance Services

07/15/2026

Drupal released a core security update today (SA-CORE-2026-010, 011 & 012).

Because this is Drupal core — not an add-on module — EVERY Drupal 10 and 11 site is affected.

The issue: cross-site scripting (XSS) and information-disclosure vulnerabilities that could let an attacker run malicious code in visitors' browsers or expose data.

What to do:
- Drupal 10 sites: update core to 10.6.13
- Drupal 11 sites: update core to 11.4.4
- Rated "Moderately Critical" by the Drupal Security Team

06/24/2026

Security update for Drupal sites.

Salesforce Suite (salesforce) needs to be updated to version 5.1.3.

The issue: Without the update, someone could potentially trick an admin into performing unwanted actions.

This applies to Drupal 10/11 sites.

Geolocation Field (geolocation) needs to be updated to version 3.15.0.

The issue: Without the update, someone could potentially access or modify your database without permission.

This applies to Drupal 10/11 sites.

Paragraphs (paragraphs) needs to be updated to version 1.21.0.

The issue: Without the update, someone could potentially access parts of your site they shouldn't be able to see.

This applies to Drupal 10/11 sites.

This only affects sites using this specific module. If you're not sure whether your site uses it, we can help you check.

06/17/2026

Security update for Drupal sites.

Drupal core (core) needs to be updated to version 10.5.12 and 10.6.11 and 11.2.14 and 11.3.12.

The issue: Without the update, someone could potentially compromise your site's security.

This applies to ALL Drupal 10/11 sites.

06/10/2026

Security update for Drupal sites.

Examples for Developers (examples) needs to be updated to version 4.0.6.

The issue: Without the update, someone could potentially access parts of your site they shouldn't be able to see.

This applies to Drupal 10/11 sites.

Tagify (tagify) needs to be updated to version 1.2.52.

The issue: Without the update, someone could potentially inject malicious code that runs in visitors' browsers.

This applies to Drupal 10/11 sites.

This only affects sites using this specific module. If you're not sure whether your site uses it, we can help you check.

06/03/2026

Drupal released a security update today.

Anti-Spam by CleanTalk (cleantalk) has a security issue that could let someone compromise your site's security.

If you have this module on your site:
- Versions below 9.7.1 are affected
- Update to version 9.7.1
- This applies to Drupal 9 sites

Commerce Core (core) has a security issue that could let someone compromise your site's security.

If you have this module on your site:
- Versions below 3.3.6 are affected
- Update to version 3.3.6
- This applies to Drupal 10/11 sites

TacJS (tacjs) has a security issue that could let someone compromise your site's security.

If you have this module on your site:
- Versions below 6.8.0 are affected
- Update to version 6.8.0
- This applies to Drupal 10/11 sites

If you don't have this module installed, no action needed.

05/20/2026

Drupal published a critical security update for core today. A few things make this one stand out:

1. "Core" means Drupal itself — not a module. Every Drupal site is affected.
2. Drupal backported the patch to Drupal 8 and Drupal 9, even though both have been end-of-life for years. They effectively never do this. That's how high-risk this advisory is.
3. Fixed versions are published for every branch from Drupal 8 through Drupal 11: 8.9.21, 9.5.12, 10.5.10, 10.6.9, 11.2.12, 11.3.10.

What to do:
→ If your site is on our maintenance plan, no action needed on your end. We're already scheduling the deployment with proper testing and rollback in place.
→ If you don't have ongoing maintenance, please reach out today — critical-severity patches close exploit windows that open within days of release.

Even if your site is on a Drupal version you thought was unsupported, a patch exists for it. Don't ignore this one.

05/13/2026

Security update for Drupal sites.

Date iCal (date_ical) needs to be updated to version 4.0.15.

The issue: Without the update, someone could potentially see private information they shouldn't have access to.

This applies to Drupal 10/11 sites.

Colorbox Inline (colorbox_inline) needs to be updated to version 2.1.1.

The issue: Without the update, someone could potentially inject malicious code that runs in visitors' browsers.

This applies to Drupal 10/11 sites.

Translate Drupal with GTranslate (gtranslate) needs to be updated to version 3.0.5.

The issue: Without the update, someone could potentially compromise your site's security.

This applies to Drupal 10/11 sites.

This only affects sites using this specific module. If you're not sure whether your site uses it, we can help you check.

04/15/2026

Drupal released a security update today.

Drupal core (core) has a CRITICAL security issue that could let someone inject malicious code that runs in visitors' browsers.

If you have this module on your site:
- Versions below 11.3.7 and 10.6.7 are affected
- Update to version 11.3.7 and 10.6.7
- This applies to Drupal 10/11 sites

If you don't have this module installed, no action needed.

Want your business to be the top-listed Gym/sports Facility in Pittsburgh?

Click here to claim your Sponsored Listing.

Location

Telephone

Address

Pittsburgh, PA