XSS Vulnerability in Simple Klaro Plugin for Drupal
CVE-2025-48918
What is CVE-2025-48918?
The Simple Klaro plugin for Drupal contains a vulnerability that allows for improper neutralization of input during web page generation, leading to Cross-Site Scripting (XSS) attacks. This issue has been identified in versions from 0.0.0 up to, but not including, 1.10.0. Attackers can exploit this vulnerability to inject malicious scripts into web pages, potentially compromising user sessions or redirecting users to malicious sites. It is crucial for site administrators to upgrade to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Simple Klaro 0.0.0 < 1.10.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
