PT-2026-34625 · Drupal+2 · Obfuscate+1

Christophe Jossart

+4

·

Published

2026-04-22

·

Updated

2026-05-19

·

CVE-2026-6871

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Obfuscate versions 0.0.0 through 2.0.1
Description Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS). The module, which obfuscates email addresses in content, fails to sufficiently sanitize user input via the Twig filter. This issue specifically affects sites utilizing ROT13 encoding (a simple substitution cipher that replaces a letter with the 13th letter after it in the alphabet) in scenarios where an attacker can provide content filtered by the module's Twig filter.
Recommendations Update to version 2.0.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6871
DRUPAL-CONTRIB-2026-033

Affected Products

Obfuscate
Drupal/Obfuscate