Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sujan Shrestha

#43245de 53,640
6.1CVSS total
Vulnerabilidades · 1
PT-2026-23112
6.1
2026-03-04
Drupal · Google Analytics 4 · CVE-2026-3529
**Name of the Vulnerable Software and Affected Versions** Drupal Google Analytics GA4 versions prior to 1.1.14 **Description** The Google Analytics GA4 module does not properly sanitize custom attributes added to the script tag used to load the Google Analytics library, leading to a Cross-Site Scripting (XSS) issue. An attacker with the "ga4 configure" or "administer google analytics ga4 settings" permission could inject malicious JavaScript through event handlers, such as `onload`, or override the script source. This could result in a Cross-Site Scripting (XSS) attack on all pages where the GA4 script is loaded. **Recommendations** Update to version 1.1.14 or later.