SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15917

MEDIUM · CVSS 4.7 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Drupal core versions from 11.2.x to 11.4.4 are susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper input neutralization during web page generation. This flaw could allow attackers to inject malicious scripts, potentially compromising user data and session integrity. Organizations using affected versions of Drupal should prioritize patching this vulnerability to safeguard their web applications and user interactions.

CVE
CVE-2026-15917
Severity
MEDIUM
CVSS
4.7
EPSS
0.13%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.