Cross-Site Scripting Vulnerability in Drupal Orejime Plugin
CVE-2026-6095
6.1MEDIUM
What is CVE-2026-6095?
A Cross-Site Scripting (XSS) vulnerability exists in the Drupal Orejime plugin, allowing attackers to inject malicious scripts into web pages. This flaw arises from improper neutralization of user inputs during the page generation process. It affects Orejime versions from 0.0.0 up to and including 2.0.15, posing risks that could lead to unauthorized access and manipulation of user data. To mitigate exposure, users are encouraged to update to the latest version and implement additional security measures.
Affected Version(s)
Orejime 0.0.0 < 2.0.16
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pierre Rudloff (prudloff)
Fabien Gutknecht (fabsgugu)
Pierre Rudloff (prudloff)
Juraj Nemec (poker10)
Pierre Rudloff (prudloff)
Jess (xjm)
