CVE-2026-55805
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
| CWE | CWE-79 |
| Vendor | drupal |
| Product | drupal core |
| Ecosystems | |
| Industries | WebMedia |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for drupal drupal core
Be the first to know when new unknown vulnerabilities affecting drupal drupal core are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Drupal / Drupal core
0.0.0 < 10.6.13 11.3.0 < 11.3.14 11.4.0 < 11.4.4 0.0.0 < 11.0.* 0.0.0 < 11.1.* 0.0.0 < 11.2.*
Credits
haii haii (hai27ii2o) danielveza Lee Rowlands (larowlan) Mingsong (mingsong) James Gilliland (neclimdul) Greg Knaddison (greggles) Lee Rowlands (larowlan) Dave Long (longwave) Jess (xjm)