Cross-Site Scripting Vulnerability in Drupal Calculation Fields by Drupal
CVE-2026-3528
Currently unrated
What is CVE-2026-3528?
The vulnerability arises from improper neutralization of user input during the generation of web pages within the Drupal Calculation Fields module. This flaw can be exploited to inject malicious scripts into web pages viewed by users, potentially leading to a range of attacks including session hijacking and data theft. It is vital for users of Calculation Fields versions prior to 1.0.4 to take immediate action to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Calculation Fields 0.0.0 < 1.0.4
