Cross-Site Scripting Vulnerability in Drupal Address Suggestion Plugin
CVE-2026-81167

4.8MEDIUM

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81167?

The Drupal Address Suggestion plugin is susceptible to a Cross-Site Scripting (XSS) vulnerability that arises from improper neutralization of user input during web page generation. An attacker could exploit this weakness to execute arbitrary scripts in the context of a user's session. This could lead to data theft or manipulation, compromising the integrity of the website and its users. It is crucial for users of Address Suggestion versions from 0.0.0 to 1.0.25 to assess their exposure and apply the recommended updates.

Affected Version(s)

Address Suggestion 0.0.0 < 1.0.25

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Conrad Lara (cmlara)
Conrad Lara (cmlara)
Joseph Olstad (joseph.olstad)
NGUYEN Bao (lazzyvn)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Jess (xjm)
.