Drupal · Siteimprove Analytics · CVE-2026-15082
**Name of the Vulnerable Software and Affected Versions**
Drupal Siteimprove Analytics versions 0.0.0 through 2.0.1
**Description**
Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS). The module fails to sufficiently sanitize the Siteimprove Analytics identification code when inserting the JavaScript tracking code. Exploitation requires the attacker to possess a role with the `administer siteimprove analytics` permission.
**Recommendations**
Update Drupal Siteimprove Analytics to a version later than 2.0.1.