PT-2026-33242 · Drupal · Drupal

·

CVE-2026-6367

·

Published

2026-04-15

·

Updated

2026-05-21

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal core versions 11.3.0 through 11.3.6
Description Drupal core contains an issue where entity suggestions provided during the process of adding a link to CKEditor 5 are not sufficiently sanitized. This allows a malicious user to trigger a stored cross-site scripting (XSS) attack against other users. Cross-site scripting is a flaw where an application includes untrusted data in a web page without proper validation, allowing attackers to execute malicious scripts in the victim's browser.
Recommendations Update to version 11.3.7.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07318
BIT-DRUPAL-2026-6367
CVE-2026-6367
DRUPAL-CORE-2026-003
GHSA-PW6F-3999-XP7G

Affected Products

Drupal