Vulnerabilities
- CVSS
- 5.4 Medium
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N- Risk score
- 43.2
- Published
- 2026-08-25
- Status
- Published
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Coverage 1
vulnerability
Multiple vulnerabilities have been discovered in Drupal, allowing attackers to compromise data confidentiality and inject malicious code remotely. These vulnerabilities affect older versions of the CMS, requiring immedia…
Advisories and references