The module doesn't sufficiently check access for the edit and delete operations. Users with "access content" permission can edit or delete any term. To solve this issue use the latest version.
...more
Drupal core's form API had a vulnerability where certain contributed or custom modules' forms may have been vulnerable to improper input validation.
...more
The Drupal security team announced on February 16th, 2022, the moderately critical information disclosure vulnerability in Drupal Core, SA-CORE-2022-004.
...more
Drupal security team announced on February 16th, 2022, the moderately critical improper input validation vulnerability in Drupal Core, SA-CORE-2022-003.
...more
Drupal Security Team announced a Cross-Site Scripting (XSS) vulnerability SA-CONTRIB-2022-024 that has low criticality index in the Custom Breadcrumbs Module on February 9th, 2022.
...more
Drupal Security team announces a moderately critical access bypass vulnerability SA-CONTRIB-2022-023 in the Fancy File Delete Module on February 9th 2022.
...more
On January 25th, a whole list of security advisories for contributed module projects was posted by the Drupal Security team that are classified as Critical but Unsupported vulnerabilities. Read to find which ones!
...more