PT-2026-34625 · Drupal+2 · Obfuscate+1
Christophe Jossart
+4
·
Published
2026-04-22
·
Updated
2026-05-19
·
CVE-2026-6871
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Obfuscate versions 0.0.0 through 2.0.1
Description
Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS). The module, which obfuscates email addresses in content, fails to sufficiently sanitize user input via the Twig filter. This issue specifically affects sites utilizing ROT13 encoding (a simple substitution cipher that replaces a letter with the 13th letter after it in the alphabet) in scenarios where an attacker can provide content filtered by the module's Twig filter.
Recommendations
Update to version 2.0.2.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Obfuscate
Drupal/Obfuscate