PT-2026-40837 · Drupal · Gtranslate

·

CVE-2026-8492

·

Published

2026-05-13

·

Updated

2026-07-23

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Translate Drupal with GTranslate versions 0.0.0 through 3.0.4
Description A Modification of Assumed-Immutable Data (MAID) issue in the GTranslate module allows Resource Location Spoofing. The module's widget JavaScript fails to sufficiently validate that document.currentScript refers to the executing script element. This allows a user capable of adding HTML to a page to cause the generated language-switcher links to point to an unintended domain. This issue is limited to sites using paid versions of the GTranslate widget JavaScript and configurations where generated language links use script-provided values. Exploitation requires the ability to add HTML with attributes not permitted by the default Drupal CKEditor configuration.
Recommendations Update to version 3.0.5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8492
DRUPAL-CONTRIB-2026-035

Affected Products

Gtranslate