Intel

AIKIDO-2026-357148

drupal/core is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-15917 Published 6 days ago

56

Medium Risk

This Affects:

PHPdrupal/core
11.2.0 - 11.3.13
Fixed in 11.3.14
11.4.0 - 11.4.3
Fixed in 11.4.4
Are you affected? Scan for Free

TL;DR

Affected versions of drupal/core are vulnerable to cross-site scripting (XSS) because the XSS filter does not sufficiently sanitize certain HTMX attributes introduced with the HTMX library in Drupal 11.2+. An attacker who can insert HTML with specific attributes may exploit this; the issue is mitigated by that requirement.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/core is vulnerable to Cross-site Scripting (XSS) in versions 11.2.0 - 11.3.13 and 11.4.0 - 11.4.3.

How to fix this

Upgrade the drupal/core library to the patch version. Drupal 11.2.x is end-of-life and does not receive a security fix — upgrade to a supported release (11.3.14 or 11.4.4).