Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Paul Mckibben

#22781of 56,337
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-55226
5.4
2026-07-01
Drupal · Colorbox · CVE-2026-58591
**Name of the Vulnerable Software and Affected Versions** Drupal Colorbox versions 0.0.0 through 2.2.0 **Description** Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS), where malicious JavaScript can be injected into the page. This occurs because the module, which integrates with the Colorbox JavaScript library to display content in an overlay, does not sufficiently protect against injection in certain scenarios. Exploitation requires the attacker to possess a role that permits the entry of HTML content. **Recommendations** Update Drupal Colorbox to a version later than 2.2.0.
PT-2025-17656
6.1
2025-04-23
Drupal · Drupal Colorbox · CVE-2025-3900
**Name of the Vulnerable Software and Affected Versions** Drupal Colorbox versions 0.0.0 through 2.1.2 **Description** The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows an attacker to perform Cross-Site Scripting (XSS) attacks. **Recommendations** For versions 0.0.0 through 2.1.2, update to version 2.1.3 or later to resolve the issue.