Description
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
Published: 2026-07-10
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Raw Formatter [Meta Tag Formatter] module could allow content that is not properly sanitized to be placed inside HTML meta tag attributes. The advisory does not specify the exact payload or the nature of the vulnerability, so the precise security consequence is uncertain. In general, unfiltered meta tag values may permit the injection of arbitrary code or data that could influence a user agent or downstream services.

Affected Systems

All Drupal sites that have the Raw Formatter [Meta Tag Formatter] module enabled are potentially affected because the advisory lists "*.*" for the affected versions, indicating that every released version of the module is vulnerable unless a patched release has been issued. Sites that rely on this module to generate SEO or social media meta tags have a higher risk if the module cannot be removed or disabled.

Risk and Exploitability

The CVSS score of 5.9 signals a moderate level of severity, while the EPSS score of less than 1 % indicates a very low probability of widespread exploitation at present. The vulnerability is not referenced in CISA’s KEV catalog. The likely attack path involves an attacker who can provide or influence content that passes through the module to inject into meta tag values. Because the advisory does not provide detailed technical data, the exact exploitability and impact remain uncertain, but any injected data could potentially be rendered by user agents or processed by downstream systems.

Generated by OpenCVE AI on August 5, 2026 at 02:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the Raw Formatter [Meta Tag Formatter] module from all active Drupal sites.
  • If the module must remain in use, configure it so that only trusted, sanitized values are inserted into meta tags, or implement server‑side sanitization prior to rendering.
  • Monitor vendor advisories and apply any updated releases as soon as they become available.

Generated by OpenCVE AI on August 5, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 05 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 22 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 18 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 16 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal raw Formatter [meta Tag Formatter]
Vendors & Products Drupal
Drupal raw Formatter [meta Tag Formatter]

Sun, 12 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 11 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 10 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
Title Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077
References

Subscriptions

Drupal Raw Formatter [meta Tag Formatter]
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T19:09:51.778Z

Reserved: 2026-07-08T15:45:00.086Z

Link: CVE-2026-15086

cve-icon Vulnrichment

Updated: 2026-07-13T19:09:21.605Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-10T23:16:47.330

Modified: 2026-07-13T20:16:43.430

Link: CVE-2026-15086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')