Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

David Galeano

#21928of 53,633
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-22084
5.4
2026-02-25
Drupal · Tagify · CVE-2026-3212
**Name of the Vulnerable Software and Affected Versions** Drupal Tagify versions prior to 1.2.49 **Description** The Tagify module for Drupal does not properly sanitize user-provided input before using it in JavaScript templates within the Tagify widget. This allows for the execution of arbitrary JavaScript code in a user's browser when content is created or edited. The issue stems from insufficient input neutralization during web page generation, leading to a Cross-Site Scripting (XSS) condition. **Recommendations** Update Drupal Tagify to version 1.2.49 or later.
PT-2026-5202
5.4
2026-01-28
Unknown · Drupal Tagify · CVE-2025-13983
**Name of the Vulnerable Software and Affected Versions** Drupal Tagify versions prior to 1.2.44 **Description** A flaw exists in Drupal Tagify that allows for Cross-Site Scripting (XSS). This issue is due to improper neutralization of input during web page generation. The vulnerability could potentially allow attackers to inject malicious scripts into web pages viewed by other users. **Recommendations** Update Drupal Tagify to version 1.2.44 or later.