PT-2025-41618 · Drupal · Drupal Facets

Damien Mckenna

+4

·

Published

2025-10-10

·

Updated

2025-10-11

·

CVE-2025-9550

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Facets versions prior to 2.0.10 Drupal Facets versions prior to 3.0.1
Description A flaw exists in Drupal Facets that allows for Cross-Site Scripting (XSS). This occurs due to improper neutralization of input during web page generation. The issue impacts the way data is handled, potentially allowing malicious scripts to be injected into web pages.
Recommendations Update Drupal Facets to version 2.0.10 or later. Update Drupal Facets to version 3.0.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-9550
DRUPAL-CONTRIB-2025-100

Affected Products

Drupal Facets