Intel

AIKIDO-2025-10590

drupal/facets is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-9550 Published Aug 28, 2025

48

Medium Risk

This Affects:

PHPdrupal/facets
2.0.0 - 2.0.9
Fixed in 2.0.10
3.0.0 - 3.0.0
Fixed in 3.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) in a module for creating faceted search interfaces due to insufficient input sanitization. An attacker with a role granted the administer facets permission could craft malicious text within facet configurations, potentially allowing for session hijacking or malicious actions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/facets is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.0.9 and 3.0.0 - 3.0.0.

How to fix this

Upgrade the drupal/facets library to the patch version.