Intel

AIKIDO-2025-10478

drupal/colorbox is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-3900 Published Jul 18, 2025

50

Medium Risk

This Affects:

PHPdrupal/colorbox
1.0.0 - 2.1.2
Fixed in 2.1.3
Are you affected? Scan for Free

TL;DR

The Colorbox module doesn't sufficiently sanitize data attributes before opening modals.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/colorbox is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 2.1.2.

How to fix this

Upgrade the drupal/colorbox library to the patch version.