drupal/core is vulnerable to Cross-site Scripting (XSS)
56
Medium Risk
Affected versions of drupal/core are vulnerable to cross-site scripting (XSS) because the XSS filter does not sufficiently sanitize certain HTMX attributes introduced with the HTMX library in Drupal 11.2+. An attacker who can insert HTML with specific attributes may exploit this; the issue is mitigated by that requirement.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.2.0 - 11.3.13 and 11.4.0 - 11.4.3.
Upgrade the drupal/core library to the patch version. Drupal 11.2.x is end-of-life and does not receive a security fix — upgrade to a supported release (11.3.14 or 11.4.4).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant