PT-2026-60354 · Drupal+2 · Drupal Core+1

·

CVE-2026-15917

·

Published

2026-07-15

·

Updated

2026-08-25

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal core versions 0.0.0 through 11.3.14 Drupal core versions 11.4.0 through 11.4.4
Description Drupal core contains a cross-site scripting (XSS) issue due to improper neutralization of input during web page generation. The XSS filter does not sufficiently sanitize certain attributes from the integrated HTMX JavaScript library, allowing an attacker to execute malicious scripts if they can insert HTML with specific attributes.
Recommendations Update Drupal core to a version later than 11.3.14. Update Drupal core to a version later than 11.4.4.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15917
DRUPAL-CORE-2026-011

Affected Products

Drupal Core
Drupal