PT-2026-22084 · Drupal+3 · Tagify+1

·

CVE-2026-3212

·

Published

2026-02-25

·

Updated

2026-03-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Tagify versions prior to 1.2.49
Description The Tagify module for Drupal does not properly sanitize user-provided input before using it in JavaScript templates within the Tagify widget. This allows for the execution of arbitrary JavaScript code in a user's browser when content is created or edited. The issue stems from insufficient input neutralization during web page generation, leading to a Cross-Site Scripting (XSS) condition.
Recommendations Update Drupal Tagify to version 1.2.49 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3212
DRUPAL-CONTRIB-2026-013

Affected Products

Tagify
Drupal Tagify