🔐 CVE Alert

CVE-2026-3212

MEDIUM 5.4

Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
8th

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.49.

CWE CWE-79
Vendor drupal
Product tagify
Ecosystems
Industries
WebMedia
Published Mar 25, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for drupal tagify

Be the first to know when new medium vulnerabilities affecting drupal tagify are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Drupal / Tagify
0.0.0 < 1.2.49

References

NVD ↗ CVE.org ↗ EPSS Data ↗
drupal.org: https://www.drupal.org/sa-contrib-2026-013

Credits

David López (akalam) Mingsong (mingsong) David López (akalam) David Galeano (gxleano) Mingsong (mingsong) Damien McKenna (damienmckenna) Dan Smith (galooph) Greg Knaddison (greggles) Drew Webber (mcdruid) Jess (xjm)