DEV Community

# drupal

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Drupal OAuth Scope Debt, WordPress Block States, and the Security Work That Still Matters

Drupal OAuth Scope Debt, WordPress Block States, and the Security Work That Still Matters

Comments
4 min read
Review: Ally WordPress Plugin Unauthenticated SQL Injection (400k+ Sites) and a Repeatable Response Playbook for WordPress Teams

Review: Ally WordPress Plugin Unauthenticated SQL Injection (400k+ Sites) and a Repeatable Response Playbook for WordPress Teams

Comments
4 min read
SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

Comments
3 min read
SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

Comments
3 min read
SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

Comments
3 min read
SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

Comments
3 min read
SA-CONTRIB-2026-019: Responsive Favicons Persistent XSS — Admin Config as Attack Surface

SA-CONTRIB-2026-019: Responsive Favicons Persistent XSS — Admin Config as Attack Surface

Comments
3 min read
SA-CONTRIB-2026-012: Theme Negotiation by Rules CSRF — GET Requests That Mutate State

SA-CONTRIB-2026-012: Theme Negotiation by Rules CSRF — GET Requests That Mutate State

Comments
4 min read
Review: Real-Time Collaboration in the WordPress Block Editor and What Changes for Plugin and Block Developers

Review: Real-Time Collaboration in the WordPress Block Editor and What Changes for Plugin and Block Developers

Comments
4 min read
Drupal SA-CONTRIB-2026-011 through 019: Full Triage Map and Impact Assessment

Drupal SA-CONTRIB-2026-011 through 019: Full Triage Map and Impact Assessment

Comments
4 min read
assertEqualHTML() in WordPress: Kill Your Brittle HTML Tests

assertEqualHTML() in WordPress: Kill Your Brittle HTML Tests

Comments
4 min read
WordPress 7.0 Beta 2 Compatibility Risks and Migration Test Checklist

WordPress 7.0 Beta 2 Compatibility Risks and Migration Test Checklist

Comments
4 min read
Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...

Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...

Comments
4 min read
Review: GitHub Agentic Workflows Security Architecture Translated into Enforceable CI/CD Guardrails for Drupal and WordPress ...

Review: GitHub Agentic Workflows Security Architecture Translated into Enforceable CI/CD Guardrails for Drupal and WordPress ...

1
Comments
3 min read
Mastering Upstream Dependency Management in Drupal Multisites

Mastering Upstream Dependency Management in Drupal Multisites

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.