Impact
The Drupal Raw Formatter [Meta Tag Formatter] vulnerability is described as allowing input to be included in HTML meta tags without proper handling. The description does not specify the exact payload or weakness, but it indicates that the module may accept unfiltered content, potentially leading to execution of unintended code. This implies a risk similar to injection issues that can compromise page integrity or security.
Affected Systems
Any Drupal site that has the Raw Formatter [Meta Tag Formatter] module active, regardless of specific version, is affected; all released versions are listed as vulnerable. Sites that rely on this module for SEO or social media meta tags are particularly at risk. The module is unsupported, so no official patch is currently available.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1 % shows a very low probability of widespread exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The likely attack requires an attacker who can provide content that flows through the module, typically by creating or editing content that includes meta tag data.
OpenCVE Enrichment