Drupal · Search Api Autocomplete · CVE-2026-16640
**Name of the Vulnerable Software and Affected Versions**
Search API Autocomplete versions 0.0.0 through 1.12.0
**Description**
Improper neutralization of input during web page generation allows Reflected Cross-site Scripting (XSS), a flaw where malicious scripts are injected into a web page and reflected back to the user. The issue exists in a test script accessible to anonymous users that fails to sufficiently validate user input. This is partially mitigated if the web server is configured to hide warning messages from users.
**Recommendations**
Update Search API Autocomplete to a version later than 1.12.0.
As a temporary mitigation, configure the web server to disable the display of warning messages to users.