view_password 6.0.4
The classes entered in the administration form are now escaped via HTML::escape before printed.
Fixes View Password - Less critical - Cross Site Scripting - SA-CONTRIB-2024-026.
paragraphs_table 8.x-1.23
Paragraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-035
- add Jason formatter
- fixed add paragraphs are far too permissive
paragraphs_table 2.0.2
Paragraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-035
add paragraphs are far too permissive
acquia_dam 1.0.13
This is a bugfix and security update for Acquia DAM. These fixes have been pushed to both the 1.0 and 1.1 beta releases
Addresses: SA-CONTRIB-2024-025
migrate_queue_importer 2.1.1
This fixes Migrate queue importer - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-024 and includes only phpcs fixes since 2.1.0.
image_sizes 3.0.2
Fixes Image Sizes - Moderately critical - Access bypass - SA-CONTRIB-2024-023
Make sure file access is given before rendering images.
email_contact 2.0.4
Fixes Email Contact - Moderately critical - Access bypass - SA-CONTRIB-2024-020.
Changes since version 2.0.3:
- Route adjustments.
- Added GitLab CI.
- Issue #3427650 by alorenc: Make variables of ContactForm protected
- Issue #3430086: Automated Drupal 11 compatibility fixes for email_contact
commerce_view_receipt 1.0.3
Includes two new features:
- Adds `View receipt` entity list operation
- Exposes a `Receipt` link field for views
Includes a security update, adding an additional entity access check on the receipt route.
Commerce View Receipt - Moderately critical - Access bypass - SA-CONTRIB-2024-021