DEV Community

# drupal

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

Comments
3 min read
SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

Comments
3 min read
SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

Comments
3 min read
SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

Comments
3 min read
SA-CONTRIB-2026-019: Responsive Favicons Persistent XSS — Admin Config as Attack Surface

SA-CONTRIB-2026-019: Responsive Favicons Persistent XSS — Admin Config as Attack Surface

Comments
3 min read
SA-CONTRIB-2026-012: Theme Negotiation by Rules CSRF — GET Requests That Mutate State

SA-CONTRIB-2026-012: Theme Negotiation by Rules CSRF — GET Requests That Mutate State

Comments
4 min read
Review: My WordPress (Browser-Native WordPress) and What It Changes for Plugin Development, Onboarding, and Reproducible Test...

Review: My WordPress (Browser-Native WordPress) and What It Changes for Plugin Development, Onboarding, and Reproducible Test...

1
Comments
3 min read
WordPress 7.0 Compatibility Scanner: Deprecations and Iframe Editor Readiness

WordPress 7.0 Compatibility Scanner: Deprecations and Iframe Editor Readiness

1
Comments
4 min read
WP-CLI Auditor: Triage Wordfence RSS Advisories Against Installed Plugins

WP-CLI Auditor: Triage Wordfence RSS Advisories Against Installed Plugins

Comments
3 min read
Review: Real-Time Collaboration in the WordPress Block Editor and What Changes for Plugin and Block Developers

Review: Real-Time Collaboration in the WordPress Block Editor and What Changes for Plugin and Block Developers

Comments
4 min read
Drupal SA-CONTRIB-2026-011 through 019: Full Triage Map and Impact Assessment

Drupal SA-CONTRIB-2026-011 through 019: Full Triage Map and Impact Assessment

Comments
4 min read
assertEqualHTML() in WordPress: Kill Your Brittle HTML Tests

assertEqualHTML() in WordPress: Kill Your Brittle HTML Tests

Comments
4 min read
Review: Pantheon Site Metrics for Drupal and WordPress Teams Managing Performance, Ownership, and Ops Triage

Review: Pantheon Site Metrics for Drupal and WordPress Teams Managing Performance, Ownership, and Ops Triage

1
Comments
6 min read
WordPress 7.0 Beta 2 Compatibility Risks and Migration Test Checklist

WordPress 7.0 Beta 2 Compatibility Risks and Migration Test Checklist

Comments
4 min read
Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...

Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.