CVE-2026-55808
published 2026-07-10CVE-2026-55808: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS)…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.27%
19.4th percentile
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal | < 10.5.12 | 10.5.12 |
| drupal | drupal | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal | >= 11.0.0 < 11.2.14 | 11.2.14 |
| drupal | drupal | >= 11.3.0 < 11.3.12 | 11.3.12 |
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.5.12 | 10.5.12 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal_core | >= 11.2.0 < 11.2.14 | 11.2.14 |
| drupal | drupal_core | >= 11.3.0 < 11.3.12 | 11.3.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
vendor_drupal·2026-06-17
CVE-2026-55808 [MEDIUM] Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Title: Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Vulnerability Type: Improper validation
Description: The JSON:API and REST modules allow you to upload image files to image fields. The validation rules check the file extension of the uploaded file but not the file MIME type. This may allow a malicious user to upload a file that is not an image. Certain web-server configurations may serve the uploaded file with its actual MIME type rather than an image type. This may lead to cross-site scripting (XSS) or other unexpected behavior.
Solution: Install the latest version: Drupal 11 If you use Drupal 11.3.x, update to Drupal 11.3.12 . If you use Drupal 11.2.x, update to Drupal 11.2.14 . Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.11 . If you use
GHSA
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
ghsa_unreviewed·2026-07-11
CVE-2026-55808 CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
VulDB
Drupal up to 11.3.11 cross site scripting (EUVD-2026-43085)
vuldb·2026-07-11
CVE-2026-55808 [LOW] Drupal up to 11.3.11 cross site scripting (EUVD-2026-43085)
A vulnerability has been found in Drupal up to 10.5.11/10.6.10/11.1.x/11.2.13/11.3.11 and classified as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-55808. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55808 drupal7: Drupal core: Cross-site Scripting (XSS) via improper input neutralization [fedora-all]
bugzilla·2026-07-13·CVSS 5.4
CVE-2026-55808 [MEDIUM] CVE-2026-55808 drupal7: Drupal core: Cross-site Scripting (XSS) via improper input neutralization [fedora-all]
CVE-2026-55808 drupal7: Drupal core: Cross-site Scripting (XSS) via improper input neutralization [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Discussion:
Drupal 7 End of Life 2025-01-05 (https://www.drupal.org/about/drupal-7/d7eol/partners)
It has been retired from
Bugzilla
CVE-2026-55808 drupal: Drupal core: Cross-site Scripting (XSS) via improper input neutralization
bugzilla·2026-07-10·CVSS 5.4
CVE-2026-55808 [MEDIUM] CVE-2026-55808 drupal: Drupal core: Cross-site Scripting (XSS) via improper input neutralization
CVE-2026-55808 drupal: Drupal core: Cross-site Scripting (XSS) via improper input neutralization
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
2026-07-10
Published