Cross-site Scripting Vulnerability in Drupal Slick Carousel Product
CVE-2026-81160
Currently unrated
What is CVE-2026-81160?
A Cross-site Scripting (XSS) vulnerability exists in the Slick Carousel module for Drupal, impacting versions from 0.0.0 to 2.1.0. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to data theft, session hijacking, or other malicious activities. Proper validation and sanitization mechanisms should be implemented to mitigate this risk effectively.
Affected Version(s)
Slick Carousel 0.0.0 < 2.1.0
