Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shirsendu Mondal

#20899of 53,635
12Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-33242
6.1
2026-04-15
Drupal · Drupal · CVE-2026-6367
**Name of the Vulnerable Software and Affected Versions** Drupal core versions 11.3.0 through 11.3.6 **Description** Drupal core contains an issue where entity suggestions provided during the process of adding a link to CKEditor 5 are not sufficiently sanitized. This allows a malicious user to trigger a stored cross-site scripting (XSS) attack against other users. Cross-site scripting is a flaw where an application includes untrusted data in a web page without proper validation, allowing attackers to execute malicious scripts in the victim's browser. **Recommendations** Update to version 11.3.7.
PT-2026-29503
5.9
2026-04-01
Unknown · Multilingual Associations · CVE-2026-21631
Name of the Vulnerable Software and Affected Versions versions prior to 2.3 Description A lack of output escaping creates a cross-site scripting (XSS) vector within the multilingual associations component. Recommendations Update to version 2.3 or later.