drupal/core is vulnerable to Cross-site Scripting (XSS)
60
Medium Risk
Affected versions of this package are vulnerable to Cross-site Scripting (XSS): Drupal 11.3 comes with support for completing entity suggestions whilst adding a link to CKEditor 5. The suggestions aren't sufficiently sanitized and a malicious user could trigger a stored cross site scripting attack against another user.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.3.0 - 11.3.6.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant