PT-2026-2980 · Drupal+2 · At Internet Piano Analytics+1

Frank Mably

+3

·

Published

2026-01-14

·

Updated

2026-02-04

·

CVE-2026-0947

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal AT Internet Piano Analytics versions 0.0.0 through 1.0.0 Drupal AT Internet Piano Analytics versions 2.0.0 through 2.3.0
Description The AT Internet Piano Analytics module for Drupal contains a Cross-Site Scripting (XSS) issue. The module does not properly filter text entered by administrators, leading to a persistent XSS condition. An attacker must have the 'administer pianoanalytics' permission to exploit this.
Recommendations Update to version 1.0.1 or later. Update to version 2.3.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-0947
DRUPAL-CONTRIB-2026-004

Affected Products

At Internet Piano Analytics
Drupal/Pianoanalytics