Intel

AIKIDO-2026-10256

drupal/responsive_favicons is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-3218 Published Feb 26, 2026

50

Medium Risk

This Affects:

PHPdrupal/responsive_favicons
0.0.1 - 2.0.1
Fixed in 2.0.2
Are you affected? Scan for Free

TL;DR

The module does not filter administrator-entered text, resulting in a persistent cross-site scripting (XSS) vulnerability. Exploitation is limited because an attacker must have a role with the permission administer responsive favicons.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/responsive_favicons is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 2.0.1.

How to fix this

Upgrade the drupal/responsive_favicons library to the patch version.