Impact
The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. Unsanitized user input can be injected into Tagify components and later rendered, causing the browser to execute arbitrary JavaScript when the stored data is displayed. The weakness corresponds to CWE‑79.
Affected Systems
The affected product is Drupal Tagify. All releases from version 0.0.0 up to and including 1.2.52 are vulnerable. Any Drupal installation that utilizes Tagify in this version range may be affected.
Risk and Exploitability
The CVSS score of 5.4 indicates% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation reports are documented. The likely attack vector involves forms that accept Tagify input and store the data; a threat actor could supply malicious payloads that are later executed by other users viewing the stored content.
OpenCVE Enrichment