Intel

AIKIDO-2026-10253

drupal/tagify is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-3212 Published Feb 26, 2026

50

Medium Risk

This Affects:

PHPdrupal/tagify
0.0.1 - 1.2.48
Fixed in 1.2.49
Are you affected? Scan for Free

TL;DR

The module does not properly sanitize user-supplied input before embedding it into JavaScript template strings within the Tagify widget, allowing arbitrary JavaScript execution in the browser when a user creates or edits content.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/tagify is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 1.2.48.

How to fix this

Upgrade the drupal/tagify library to the patch version.