Intel

AIKIDO-2026-10222

drupal/quickedit is vulnerable to Cross-Site Scripting

Cross-Site ScriptingCVE-2026-2348 Published Feb 22, 2026

50

Medium Risk

This Affects:

PHPdrupal/quickedit
0.0.1 - 1.0.4
Fixed in 1.0.5
2.0.0 - 2.0.0
Fixed in 2.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of this module are vulnerable to cross-site scripting (xss) due to insufficient sanitization of certain image-related values during in-place content editing. Malicious input can be stored and later rendered in the browser, resulting in persistent script execution. Exploitation requires that the attacker has permission to create or edit the affected field, which limits the scope of the vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/quickedit is vulnerable to Cross-Site Scripting in versions 0.0.1 - 1.0.4 and 2.0.0 - 2.0.0.

How to fix this

Upgrade the drupal/quickedit library to the patch version.