Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.49.
Published: 2026-03-25
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting allowing arbitrary client‑side script execution
Action: Apply Patch
AI Analysis

Impact

Drupal Tagify contains a cross‑site scripting flaw that occurs when user supplied content is rendered without proper escaping. The vulnerability allows an attacker to inject malicious JavaScript that runs in the browser of any visitor who views the affected content and can result in session hijacking, credential theft, defacement or delivery of additional payloads. This is a classic example of CWE‑79.

Affected Systems

The issue affects the Tagify module for Drupal from the initial version 0.0.0 up to and including 1.2.48. All installations of Tagify before version 1.2.49 are vulnerable, so administrators should verify the module version on every site and determine whether a dangerous release is present.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, while an EPSS score of less than 1 % suggests that attacks are currently considered unlikely. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation requires an attacker to deliver crafted input that is rendered in the browser, thus the threat is client‑side and depends on users visiting the compromised content. Prevention hinges on upgrading the module or applying input filtering to eliminate the unsafe rendering.

Generated by OpenCVE AI on March 27, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tagify module to version 1.2.49 or newer on all Drupal sites.
  • Verify on each site that the installed Tagify version is not less than 1.2.49.
  • If an upgrade cannot be applied immediately, restrict the use of Tagify in untrusted content or temporarily disable the module until the patch is installed.

Generated by OpenCVE AI on March 27, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 27 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Factorial
Factorial tagify
CPEs cpe:2.3:a:factorial:tagify:*:*:*:*:*:drupal:*:*
Vendors & Products Factorial
Factorial tagify

Thu, 26 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal tagify
Vendors & Products Drupal
Drupal tagify

Wed, 25 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 25 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.49.
Title Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-03-26T14:38:54.095Z

Reserved: 2026-02-25T16:59:27.087Z

Link: CVE-2026-3212

cve-icon Vulnrichment

Updated: 2026-03-25T20:01:11.224Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T16:16:22.217

Modified: 2026-03-27T19:21:55.493

Link: CVE-2026-3212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-29T20:28:26Z

Weaknesses