CVE-2026-55805
published 2026-08-25CVE-2026-55805: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.13%
3.2th percentile
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.6.13 | 10.6.13 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 0.0.0 < 11.2.* | 11.2.* |
| drupal | drupal_core | >= 11.3.0 < 11.3.14 | 11.3.14 |
| drupal | drupal_core | >= 11.4.0 < 11.4.4 | 11.4.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
vendor_drupal·2026-07-15
CVE-2026-55805 [MEDIUM] Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
Title: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
Vulnerability Type: Cross-site scripting
Description: The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability. This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.
Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13 . Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupa
GHSA
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS.
ghsa_unreviewed·2026-08-26
CVE-2026-55805 CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS.
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-25
Published