Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Andriy Parkhomiuk

#49721of 56,337
5.4Total CVSS
Vulnerabilities · 1
PT-2026-56662
5.4
2026-07-08
Drupal · Siteimprove Analytics · CVE-2026-15082
**Name of the Vulnerable Software and Affected Versions** Drupal Siteimprove Analytics versions 0.0.0 through 2.0.1 **Description** Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS). The module fails to sufficiently sanitize the Siteimprove Analytics identification code when inserting the JavaScript tracking code. Exploitation requires the attacker to possess a role with the `administer siteimprove analytics` permission. **Recommendations** Update Drupal Siteimprove Analytics to a version later than 2.0.1.