Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9726: Drupal Basket module: Unsanitized data allows code execution

DRUPAL-CONTRIB-2026-038 CVE-2026-9726 CVE-2026-9726
Summary

The Drupal Basket module is used for e-commerce and checkout on Drupal sites. If an attacker injects malicious data, they may be able to execute arbitrary code on the site, potentially leading to unauthorized actions or data exposure. To protect your site, update the Basket module to the latest version that includes security fixes.

What to do
  • Update drupal drupal/basket to version 2.1.17.
Affected software
Ecosystem VendorProductAffected versions
Packagist:https://packages.drupal.org/8 drupal drupal/basket < 2.1.17
Fix: upgrade to 2.1.17
– drupal drupal alternativecommerce (basket) < 2.1.17
Original title
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal Alterna...
Original description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
Vulnerability type
CWE-915
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 27 May 2026