Description
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
Published: 2026-07-10
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Drupal Raw Formatter [Meta Tag Formatter] vulnerability is described as allowing input to be included in HTML meta tags without proper handling. The description does not specify the exact payload or weakness, but it indicates that the module may accept unfiltered content, potentially leading to execution of unintended code. This implies a risk similar to injection issues that can compromise page integrity or security.

Affected Systems

Any Drupal site that has the Raw Formatter [Meta Tag Formatter] module active, regardless of specific version, is affected; all released versions are listed as vulnerable. Sites that rely on this module for SEO or social media meta tags are particularly at risk. The module is unsupported, so no official patch is currently available.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1 % shows a very low probability of widespread exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The likely attack requires an attacker who can provide content that flows through the module, typically by creating or editing content that includes meta tag data.

Generated by OpenCVE AI on July 29, 2026 at 09:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove or disable the Raw Formatter [Meta Tag Formatter] module from all active Drupal sites to eliminate exposure.
  • Reconfigure Drupal’s text formats to exclude or whitelist meta tag attributes, ensuring that only trusted values are allowed.
  • Implement a content security policy that restricts inline scripts within meta tags and limits script sources to trusted origins.
  • Monitor Drupal security advisories for updates or patches.

Generated by OpenCVE AI on July 29, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 22 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 18 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 16 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal raw Formatter [meta Tag Formatter]
Vendors & Products Drupal
Drupal raw Formatter [meta Tag Formatter]

Sun, 12 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 11 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 10 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
Title Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077
References

Subscriptions

Drupal Raw Formatter [meta Tag Formatter]
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T19:09:51.778Z

Reserved: 2026-07-08T15:45:00.086Z

Link: CVE-2026-15086

cve-icon Vulnrichment

Updated: 2026-07-13T19:09:21.605Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:45:04Z

Weaknesses

No weakness.