PT-2026-48591 · Drupal+2 · Tagify+1

·

CVE-2026-11908

·

Published

2026-06-10

·

Updated

2026-07-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Tagify versions 0.0.0 through 1.2.52
Description Stored Cross-site Scripting (XSS) occurs because the module fails to properly sanitize the name of parent taxonomy terms when rendering suggestions in the Tagify dropdown. This allows an attacker with permissions to create or edit taxonomy terms in a vocabulary to execute arbitrary JavaScript within the context of a user session.
Recommendations Update Drupal Tagify to a version later than 1.2.52.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11908
DRUPAL-CONTRIB-2026-043

Affected Products

Tagify
Drupal Tagify