Cross-Site Scripting Vulnerability in Drupal Real-time SEO Plugin
CVE-2025-7716
Currently unrated
What is CVE-2025-7716?
The Real-time SEO plugin for Drupal contains a vulnerability that allows attackers to inject arbitrary scripts into web pages viewed by other users. This improper handling of user input can lead to cross-site scripting (XSS) attacks, enabling an adversary to hijack user sessions, redirect users to malicious sites, or execute unwanted actions on behalf of the users. Users of Real-time SEO from version 2.0.0 to prior to 2.2.0 are particularly at risk and should take immediate steps to update their installations to mitigate potential exploitations.
Affected Version(s)
Real-time SEO for Drupal 2.0.0 < 2.2.0