Intel

AIKIDO-2025-10910

drupal/tagify is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-13983 Published Dec 9, 2025

60

Medium Risk

This Affects:

PHPdrupal/tagify
0.0.1 - 1.2.43
Fixed in 1.2.44
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (xss): the module does not sufficiently sanitize the infoLabel value in certain configurations, allowing injected script content. The risk is reduced because only uncommon configurations expose the affected infoLabel output, and an attacker must have user-level access to provide or modify this value.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/tagify is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.2.43.

How to fix this

Upgrade the drupal/tagify library to the patch version.