Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Stored XSS. This issue affects Tagify versions: from 0.0.0 to 1.2.52.
Published: 2026-07-10
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows stored cross‑site scripting. Unsanitized user input can be injected into Tagify components and later rendered, causing the browser to execute arbitrary JavaScript when the stored data is displayed. The weakness corresponds to CWE‑79.

Affected Systems

The affected product is Drupal Tagify. All releases from version 0.0.0 up to and including 1.2.52 are vulnerable. Any Drupal installation that utilizes Tagify in this version range may be affected.

Risk and Exploitability

The CVSS score of 5.4 indicates% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation reports are documented. The likely attack vector involves forms that accept Tagify input and store the data; a threat actor could supply malicious payloads that are later executed by other users viewing the stored content.

Generated by OpenCVE AI on July 28, 2026 at 08:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tagify to a version newer than 1.2.52.
  • If an upgrade cannot be performed immediately, disable or remove Tagify usage from the site until a patch is applied.
  • Apply a Content Security Policy that restricts script execution or deploy a web application firewall to filter malicious scripts as a temporary mitigation.

Generated by OpenCVE AI on July 28, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal tagify
Vendors & Products Drupal
Drupal tagify

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Stored XSS. This issue affects Tagify versions: from 0.0.0 to 1.2.52.
Title Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-14T14:34:40.621Z

Reserved: 2026-06-10T16:26:54.582Z

Link: CVE-2026-11908

cve-icon Vulnrichment

Updated: 2026-07-14T13:59:05.989Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')