Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.
Published: 2026-07-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation (CWE‑79) in Drupal Anti‑Spam by CleanTalk allows reflected cross‑site scripting. This vulnerability can potentially allow malicious scripts to be executed in a victim's browser when input is reflected without proper sanitization.

Affected Systems

All installations of the Drupal Anti‑Spam by CleanTalk module from version 0.0.0 through 9.7.1 are affected. Any Drupal site using this module is potentially at risk.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate risk. Because the flaw permits reflected cross‑site scripting, attackers could inject malicious input that is echoed back to users. The EPSS score of less than 1% suggests that exploitation is not widespread. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CleanTalk Anti‑Spam module to the latest available release that includes the XSS fix.
  • If upgrading cannot be performed immediately, temporarily disable the module entirely until a patch is applied.
  • Configure a Content Security Policy that restricts script execution to trusted origins to reduce the impact of any residual XSS.

Generated by OpenCVE AI on July 31, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal anti-spam By Cleantalk
Vendors & Products Drupal
Drupal anti-spam By Cleantalk

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.
Title Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042
Weaknesses CWE-79
References

Subscriptions

Drupal Anti-spam By Cleantalk
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-14T14:34:48.521Z

Reserved: 2026-06-03T15:41:16.331Z

Link: CVE-2026-10770

cve-icon Vulnrichment

Updated: 2026-07-14T13:58:37.961Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')