SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13231

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Drupal Advanced Content Feedback versions 0.0.0 to 2.8.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper input neutralization during web page generation. This vulnerability could allow an attacker to inject malicious scripts that execute in the context of a user's browser, potentially compromising user data and session integrity. Organizations using the affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-13231
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)