Cross-Site Scripting Vulnerability in Drupal Real-time SEO Plugin
CVE-2025-7716

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
21 July 2025

What is CVE-2025-7716?

The Real-time SEO plugin for Drupal contains a vulnerability that allows attackers to inject arbitrary scripts into web pages viewed by other users. This improper handling of user input can lead to cross-site scripting (XSS) attacks, enabling an adversary to hijack user sessions, redirect users to malicious sites, or execute unwanted actions on behalf of the users. Users of Real-time SEO from version 2.0.0 to prior to 2.2.0 are particularly at risk and should take immediate steps to update their installations to mitigate potential exploitations.

Affected Version(s)

Real-time SEO for Drupal 2.0.0 < 2.2.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Alexander Varwijk (kingdutch)
Pierre Rudloff (prudloff)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Pierre Rudloff (prudloff), provisional member of the Drupal Security Team
Jess (xjm)
.
CVE-2025-7716 : Cross-Site Scripting Vulnerability in Drupal Real-time SEO Plugin