SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-10770

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The vulnerability in Drupal Anti-Spam by CleanTalk allows for reflected cross-site scripting (XSS) due to improper input neutralization during web page generation, potentially enabling attackers to execute malicious scripts in the context of a user's browser. This affects all versions from 0.0.0 to 9.7.1, posing a risk to users who rely on this module for spam protection. Organizations utilizing this module should prioritize remediation to safeguard against potential exploitation.

CVE
CVE-2026-10770
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)