๐Ÿ” CVE Alert

CVE-2026-81160

MEDIUM 6.1

Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.

CWE CWE-79
Vendor drupal
Product slick carousel
Ecosystems
Industries
WebMedia
Published Sep 2, 2026
Last Updated Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for drupal slick carousel

Be the first to know when new medium vulnerabilities affecting drupal slick carousel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / Slick Carousel
0.0.0 < 2.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-contrib-2026-117

Credits

Drew Webber (mcdruid) Gaus Surahman (gausarts) Swan Kalata (akalata) cilefen Neil Drumm (drumm) Greg Knaddison (greggles) Drew Webber (mcdruid) Pierre Rudloff (prudloff)