PT-2026-33240 · Drupal · Drupal

Anna Kalata

+12

·

Published

2026-04-15

·

Updated

2026-05-21

·

CVE-2026-6365

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 10.5.9 Drupal versions prior to 10.6.7 Drupal versions prior to 11.2.11 Drupal versions prior to 11.3.7
Description Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to cross-site scripting (XSS), a flaw where malicious scripts are injected into trusted websites.
Recommendations Update to version 10.5.9 Update to version 10.6.7 Update to version 11.2.11 Update to version 11.3.7

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-07319
BIT-DRUPAL-2026-6365
CVE-2026-6365
DRUPAL-CORE-2026-001
GHSA-F3CJ-MJQM-FHVJ

Affected Products

Drupal