CVE-2026-15917
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
| CWE | CWE-79 |
| Vendor | drupal |
| Product | drupal core |
| Ecosystems | |
| Industries | WebMedia |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for drupal drupal core
Be the first to know when new unknown vulnerabilities affecting drupal drupal core are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Drupal / Drupal core
11.3.0 < 11.3.14 11.4.0 < 11.4.4 0.0.0 < 11.2.*
Credits
Pierre Rudloff (prudloff) Shawn Duncan (fathershawn) Pierre Rudloff (prudloff) catch (catch) Lee Rowlands (larowlan) Dave Long (longwave) Jess (xjm)