Cross-Site Scripting Vulnerability in Drupal Real-time SEO Plugin
CVE-2025-7716

6.1MEDIUM

Key Information:

Vendor

Drupal

Vendor
CVE Published:
21 July 2025

What is CVE-2025-7716?

The Real-time SEO plugin for Drupal contains a vulnerability that allows attackers to inject arbitrary scripts into web pages viewed by other users. This improper handling of user input can lead to cross-site scripting (XSS) attacks, enabling an adversary to hijack user sessions, redirect users to malicious sites, or execute unwanted actions on behalf of the users. Users of Real-time SEO from version 2.0.0 to prior to 2.2.0 are particularly at risk and should take immediate steps to update their installations to mitigate potential exploitations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Real-time SEO for Drupal 2.0.0 < 2.2.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Alexander Varwijk (kingdutch)
Pierre Rudloff (prudloff)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Pierre Rudloff (prudloff), provisional member of the Drupal Security Team
Jess (xjm)
.