Cross-site Scripting Vulnerability in Drupal Search API Autocomplete
CVE-2026-16640

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-16640?

A Cross-site Scripting vulnerability exists in the Search API Autocomplete module of Drupal, enabling attackers to inject malicious scripts into web pages viewed by users. This issue specifically affects versions ranging from 0.0.0 to 1.12.0, allowing for the possibility of reflected XSS attacks that could compromise user data or redirect to malicious sites. It is crucial for users of affected versions to apply necessary updates to mitigate these security risks.

Affected Version(s)

Search API Autocomplete 0.0.0 < 1.12.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elar Lang (elarlang)
Thomas Seiber (drunken monkey)
Elar Lang (elarlang)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
.