Impact
An improperly neutralized user input during page generation in Drupal Search API Autocomplete allows a reflected cross‑site scripting vulnerability. If an attacker supplies crafted data that is echoed back in the autocomplete suggestions, the browser will execute the injected script, enabling defacement, cookie theft, or session hijacking.
Affected Systems
Drupal Search API Autocomplete modules installed on a Drupal website are affected. All releases from the initial 0.0.0 to version 1.12.0 are vulnerable; any site running these versions is at risk.
Risk and Exploitability
The vulnerability is classified as moderately critical. No EPSS score is available and it is not listed in the CISA KEV catalog, but XSS is a well‑known attack that can be triggered via reflected payloads. Without an immediate patch, users face the possibility of arbitrary script execution when viewing autocomplete results. The attack is likely to be performed by sending malicious data in the query that triggers suggestions, which does not require administrator privileges but works against any authenticated or unauthenticated user who receives the injected response.
OpenCVE Enrichment