Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).

This issue affects Drupal core: from 11.3.0 before 11.3.7.
Published: 2026-05-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of improper neutralization of input during web page generation, which allows malicious code to be embedded in rendered pages. The mechanism is a classic X‑SS flaw that can be exploited by injecting scripts into user‑controllable data without adequate escaping, matching CWE‑79. Based on the description, it is inferred that the flaw permits the injection of arbitrary JavaScript that will execute when a victim views the affected page.

Affected Systems

Drupal core versions 11.3.0 through 11.3.6 (inclusive) are affected. Versions 11.3.7 and later contain the fix. No other Drupal products are listed as impacted by this advisory.

Risk and Exploitability

The advisory labels the issue as moderately critical, and the CVSS score of 6.1 indicates moderate severity; the EPSS score is 0.00029, indicating a very low probability of exploitation; the vulnerability is not present in CISA’s KEV list. The attack surface is remote and web-based; an attacker can craft payloads via any interface that accepts user-input and fails to escape it. An attacker who controls the input can influence a victim’s browser to run arbitrary JavaScript, potentially leading to session hijacking, phishing, or defacement. The exploitation requires only web access and does not necessitate privileged credentials. While the very low EPSS score suggests no widespread exploitation has been observed yet, the presence of the flaw in Drupal’s core code and the widespread deployment of Drupal means that public sites remain attractive targets.

Generated by OpenCVE AI on May 20, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal core to version 11.3.7 or later to apply the XSS fix. The advisory provides the specific upgrade path for affected sites.
  • Validate and sanitize all user‑supplied content before rendering it, ensuring that HTML entities are properly encoded to prevent injection of script content.
  • Re‑configure site permissions so that only trusted users can submit content that bypasses automatic escaping, reducing the attack surface for XSS payloads.

Generated by OpenCVE AI on May 20, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pw6f-3999-xp7g Drupal core allows Cross-Site Scripting (XSS)
References
History

Wed, 20 May 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal drupal
CPEs cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Vendors & Products Drupal drupal

Wed, 20 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 19 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal drupal Core
Vendors & Products Drupal
Drupal drupal Core

Tue, 19 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 11.3.0 before 11.3.7.
Title Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
Weaknesses CWE-79
References

Subscriptions

Drupal Drupal Drupal Core
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-05-20T13:34:14.489Z

Reserved: 2026-04-15T14:39:29.058Z

Link: CVE-2026-6367

cve-icon Vulnrichment

Updated: 2026-05-20T13:34:10.622Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-19T23:16:58.353

Modified: 2026-05-20T22:58:38.920

Link: CVE-2026-6367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T16:30:14Z

Weaknesses