CVE-2026-15917
published 2026-08-25CVE-2026-15917: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS)…
PriorityP422medium4.7CVSS 3.1
AVNACHPRNUIRSCCLILAN
EPSS
0.13%
2.9th percentile
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 11.2.* | 11.2.* |
| drupal | drupal_core | >= 11.3.0 < 11.3.14 | 11.3.14 |
| drupal | drupal_core | >= 11.4.0 < 11.4.4 | 11.4.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
vendor_drupal·2026-07-15
CVE-2026-15917 [MEDIUM] Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Title: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Vulnerability Type: Cross-site scripting
Description: Drupal core 11.2 and above integrate the HTMX JavaScript library. Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability. The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes.
Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 Drupal 10 core is not affected. However, certain contributed modules may be affected, so a Drupal 10.
GHSA
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
ghsa_unreviewed·2026-08-26
CVE-2026-15917 CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-25
Published