Cross-Site Scripting Vulnerability in Drupal Core Product
CVE-2026-6367
6.1MEDIUM
What is CVE-2026-6367?
A Cross-Site Scripting (XSS) vulnerability exists in the core of Drupal, specifically impacting versions prior to 11.3.7. Due to improper handling of input during web page generation, attackers can exploit this flaw to inject malicious scripts into web applications, compromising the security of users interacting with the site. This vulnerability highlights the importance of robust input validation and regular updates to maintain secure web environments.
Affected Version(s)
Drupal core 11.3.0 < 11.3.7
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
cantina_security
Dries Buytaert (dries)
Shirsendu Mondal
Lee Rowlands (larowlan)
Drew Webber (mcdruid)
Mingsong (mingsong)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
Juraj Nemec (poker10)
Jess (xjm)
