Drupal · Colorbox · CVE-2026-58591
**Name of the Vulnerable Software and Affected Versions**
Drupal Colorbox versions 0.0.0 through 2.2.0
**Description**
Improper neutralization of input during web page generation allows Cross-Site Scripting (XSS), where malicious JavaScript can be injected into the page. This occurs because the module, which integrates with the Colorbox JavaScript library to display content in an overlay, does not sufficiently protect against injection in certain scenarios. Exploitation requires the attacker to possess a role that permits the entry of HTML content.
**Recommendations**
Update Drupal Colorbox to a version later than 2.2.0.