Cross-site Scripting Vulnerability in Drupal Core by Drupal
CVE-2026-55805

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55805?

A Cross-site Scripting (XSS) vulnerability in Drupal Core allows attackers to inject malicious scripts into web pages. This issue affects a wide range of Drupal core versions, potentially compromising user accounts and site integrity. It is crucial for site administrators to apply recommended patches and updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Drupal core 0.0.0 < 10.6.13

Drupal core 11.3.0 < 11.3.14

Drupal core 11.4.0 < 11.4.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

haii haii (hai27ii2o)
danielveza
Lee Rowlands (larowlan)
Mingsong (mingsong)
James Gilliland (neclimdul)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
Dave Long (longwave)
Jess (xjm)
.