PT-2025-13865 · Drupal · Drupal Link Field Display Mode Formatter

Benji Fisher

+7

·

Published

2025-03-19

·

Updated

2025-04-01

·

CVE-2025-31695

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal Link field display mode formatter versions 0.0.0 through 1.6.0
Description The issue is related to an Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS), in the Drupal Link field display mode formatter. This allows for Cross-Site Scripting (XSS) attacks.
Recommendations For versions 0.0.0 through 1.6.0, update to version 1.6.0 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13925
CVE-2025-31695
DRUPAL-CONTRIB-2025-024
GHSA-P2WG-8H29-874V

Affected Products

Drupal Link Field Display Mode Formatter