Drupal CMS News Digest

developments tricks, articles and reviews from Drupal specialists

News Categories: SEO  Design  Marketing
Drupal Association blog: Leadership changes at the Drupal Association
Our CEO, Tim Doyle, has stepped down from his role. We are grateful to Tim for his leadership and impact on our organization. Tim has built a strong leadership team that is positioned to continue the mission and vision that he and the Board share for Drupal. As part of this process, the Board has been working to identify Tim’s successor. We anticipate that the important work and mission of our organization will continue under new leadership, building on the strategy and plans we led during Tim’s time with Drupal. Likewise, the Board has been working with the senior team to ensure that interim leadership will be in place to facilitate a smooth transition. We are grateful to Tim for all of his contributions as the leader of Drupal, and we look forward to his continued success in his future endeavors. The Drupal Association board has appointed Tiffany Farriss as the Interim CEO, who brings more than a decade of experience as a Drupal Association board member, to guide the organization and community through this transition period.
Security advisories: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.*CVE IDs: CVE-2026-55805Description: The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability. This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface. Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4. If you use Drupal 11.3.x, update to Drupal 11.3.14. Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13. Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-life.Reported By:  haii haii (hai27ii2o) Fixed By:  danielveza Lee Rowlands (larowlan) of the Drupal Security Team Mingsong (mingsong) provisional member of the Drupal Security Team James Gilliland (neclimdul) of the Drupal Security Team Coordinated By:  Greg Knaddison (greggles) of the Drupal Security Team Lee...
Security advisories: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross-site scriptingAffected versions: >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.2.*CVE IDs: CVE-2026-15917Description: Drupal core 11.2 and above integrate the HTMX JavaScript library. Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability. The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes.Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4. If you use Drupal 11.3.x, update to Drupal 11.3.14. Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 Drupal 10 core is not affected. However, certain contributed modules may be affected, so a Drupal 10.6 fix is included as hardening. Drupal 8 and Drupal 9 have both reached end-of-life.Reported By:  Pierre Rudloff (prudloff) of the Drupal Security Team Fixed By:  Shawn Duncan (fathershawn) Pierre Rudloff (prudloff) of the Drupal Security Team Coordinated By:  catch (catch) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Dave Long (longwave) of the Drupal Security...
Security advisories: Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Project: Drupal coreDate: 2026-July-15Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Information disclosureAffected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.*CVE IDs: CVE-2026-15916Description: The Image module allows you to define and configure image fields. The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private://. This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images. Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12)). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings.Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4. If you use Drupal 11.3.x, update to Drupal 11.3.14. Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13. Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-...
Centarro: Let Shoppers Change Their Minds Without Leaving the Cart
Checkout is fragile. Every extra step between "I want this" and "order placed" is an opportunity for a shopper to abandon their cart entirely. And one of the most common moments of hesitation happens when a buyer realizes they added the wrong item to their cart. Maybe it was the wrong format or the wrong bundle. Or, maybe the wrong billing cycle for a donation or subscription.The fix is simple. Navigate back to the product page, add the correct item, and remove the old one from the cart. But this friction, however small, can cost conversions.The Commerce Product Alternative module for Drupal Commerce solves this by letting shoppers swap a product variation directly in their cart. One click. No detours.Cart decisions, by design, shouldn't be finalShoppers change their minds. Someone adds a hardcover book to their cart, then realizes they want the bundle that also includes the digital download. A new member selects a one-time membership fee, then notices the auto-renewal option is more cost-effective. A donor commits to a single gift, then considers whether a recurring contribution would be better.In each of these cases, the shopper has already committed to buying something. They're in the cart. They're ready.Why force them to start over? Read more
Talking Drupal: Talking Drupal #561 - The Aaron Winborn Award
Today we are talking about Aaron Winborn, The award named after him, and what winning is like with guests George DeMet & April Sides. We'll also cover Summit as our module of the week. For show notes visit: https://www.talkingDrupal.com/561 Topics Who Was Aaron Winborn Award Origin Story How Winners Are Chosen Why Community Matters What Winners Share April Learns She Won Handcrafted Award Stories On Stage Emotions After Winning Reflections How To Contribute Nominations And Makers Surprise Award Ideas Wrap Up And Contacts Resources TD Cafe #018 - Drupal Site Templates Aaron Winborn Award Winner Ask a wookie Guests April Sides - weekbeforenext George DeMet - palantir.net gdemet Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Ashraf Abed - drupito.com ashrafabed MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted to create a website purpose-built for an event like a Drupal camp, that collects, moderates, and schedules user-submitted sessions, and do all of that within the Drupal CMS installer? There's a site template for that. Module name/project name: Summit Site Template Brief history How old: created in June 2026 by yours truly Versions available: 1.0.0, released yesterday Maintainership Actively maintained Security and test coverage Documentation some in the repo we'...
BloomIdea: Dynamic Multibanco references in Drupal Commerce: Commerce ifthenpay 3.0 has arrived
In 2018 we released Commerce ifthenpay, the module that brought Multibanco references to Drupal Commerce. Seven years later, we are publishing version 3.0.0: the module's biggest evolution since then, with dynamic Multibanco references generated by the ifthenpay API, MB WAY payment retries and full support for Drupal 10 and 11. The silent problem of locally generated references A Multibanco reference has 9 digits, and the classic local generation algorithm reserves only 4 of them for the order number. It works perfectly up to order 9999. Beyond that, the number has to be compressed to fit, and this is where mathematics turns against the store. Version 2.x mitigated the problem by spreading order numbers across 9000 possible combinations. It sounds like a lot, but the birthday paradox is relentless: around 112 simultaneously open references are enough for a 50% chance that two different orders share exactly the same reference. In a busy store, that means payments that can be matched to the wrong order, or never reconciled at all. Worst of all, the problem is invisible: everything seems to work, until the day a customer pays and their order stays "unpaid". The solution: references generated by ifthenpay Version 3.0.0 introduces a new mode on the Multibanco gateway: instead of computing the reference locally, the module requests it from the ifthenpay REST API, using the account's...
The Drop Times: Matthew Saunders Calls for Open-Source Funding to Move From Values to Budgets
The debate over open-source infrastructure often ends at agreement. Matthew Saunders wants it to continue into budgets, governance, and contributor support.
Droptica: Why your Drupal site feels broken (even though it's not): 14 common mistakes
Your Drupal site is on a current version, gets security updates, and technically works - yet editing is painful and every small change waits in a developer queue. The platform is rarely the problem.Fourteen common implementation mistakes that make a Drupal site feel broken - with symptoms, diagnosis, and fixes for each. Most cost a fraction of a rebuild to put right.
Tag1 Insights: A New Direction for Authentication in Drupal Core
Take Away At Tag1, we believe in proving AI within our own work before recommending it to clients. This post is part of our AI Applied content series, where team members share real stories of how they're using Artificial Intelligence and the insights and lessons they learn along the way. Here, Lucas Hedding, Senior Backend Engineer & Migration Lead and Drupal core subsystem maintainer for authentication/authorization, used Claude to work through over 1,200 open issues in the Drupal auth/authZ issue queues and co-architect a new pluggable authentication system for Drupal core, without writing a single line of code. When approaching AI, I've done so warily. Maybe it was because I was a skeptic, but my first endeavors were not glowing success stories. My first real attempt to kick the tires ended with me kicking AI to the curb and doing some regex and search/replace to finish what it started. I chalk it up to a mix of model maturity and, let's be honest, my own ill-directed uses. But more recently I've been finding wins. I find AI very useful for writing test cases for test-driven development (TDD). It's also really good at troubleshooting. It takes a bug report, follows the code paths, and writes a failing test that reproduces the bug. When you solve the problem, you can be sure you have...
Matt Glaman: phpstan-drupal 2.1.0: stricter defaults
phpstan-drupal 2.1.0 is out. The theme of this release: rules and behaviors that proved themselves as opt-ins are now the defaults. If you run `composer update` and see new errors, that is the release working as intended — everything below includes the configuration to opt back out.Nine rules are now enabled by defaultThese rules shipped as opt-ins over the 2.0 cycle. They have had time to bake, and they catch real bugs, so they no longer require configuration:
Nonprofit Drupal posts: July 2026 Drupal for Nonprofits Chat
Join us THURSDAY, July 16 at 1pm ET / 10am PT, for our regularly scheduled call to chat about all things Drupal and nonprofits. (Convert to your local time zone.) We don't have anything specific on the agenda this month, so we'll have plenty of time to discuss anything that's on our minds at the intersection of Drupal and nonprofits. Got something specific you want to talk about? Feel free to share ahead of time in our collaborative Google document at https://nten.org/drupal/notes! All nonprofit Drupal devs and users, regardless of experience level, are always welcome on this call. This free call is sponsored by NTEN.org and open to everyone. Information on joining the meeting can be found in our collaborative Google document.
The Drop Times: Bert Boerland Makes Drupal Sustainability the Focus of Board Candidacy
Boerland links his board candidacy to a question now facing Drupal: how the project can expand institutional support without narrowing the path for contributors, local communities, and site owners.
Droptica: Content personalization in Drupal, part 2: journeys and smart forms for multiple audiences
Getting each audience to the right section is only half the job. The harder part is making the experience feel personal and routing every visitor to the right form without a maze of options.Part 2 of this Drupal guide covers user journeys, smart Webform contact routing, and pragmatic content personalization for multiple audiences.
Specbee: How Drupal support & maintenance services can keep your site secure, fast, and future-ready
Got your Drupal website up and running but haven't figured how to maintain it? Read to find out how you can optimize your site and make it future-ready.
The Drop Times: Canonical Report Flags Open Source Supply Chain Gaps
Drupal site security rarely stops at core and module updates. Canonical’s survey shows why package provenance, Linux maintenance, and patch ownership remain part of delivery risk.

Number of Total Worldwide Registered Domains