PT-2026-46114 · Drupal+2 · Cleantalk Antispam+2

·

CVE-2026-10770

·

Published

2026-06-03

·

Updated

2026-07-10

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Anti-Spam by CleanTalk versions 0.0.0 through 9.7.1
Description Reflected Cross-site Scripting (XSS) occurs when the module fails to sufficiently sanitize API response messages before rendering them in HTML output. Specifically, the cleantalk die() and ct die() functions output the CleanTalk API response message directly into HTML, which allows the injection of arbitrary HTML or JavaScript. Exploitation requires the attacker to influence the CleanTalk cloud API response, such as through a man-in-the-middle attack or a compromised API server.
Recommendations Update Anti-Spam by CleanTalk to a version newer than 9.7.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10770
DRUPAL-CONTRIB-2026-042

Affected Products

Cleantalk Antispam
Cleantalk
Drupal/Cleantalk