Intel

AIKIDO-2026-10569

drupal/core is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-6367 Published Apr 27, 2026

60

Medium Risk

This Affects:

PHPdrupal/core
11.3.0 - 11.3.6
Fixed in 11.3.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS): Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross site scripting attack against another user.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.3.0 - 11.3.6.

How to fix this

Upgrade the drupal/core library to the patch version.