PT-2026-60391 · Drupal+2 · Drupal Core+1

·

CVE-2026-55805

·

Published

2026-07-15

·

Updated

2026-08-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal core versions 0.0.0 through 10.6.13 Drupal core versions 11.3.0 through 11.3.14 Drupal core versions 11.4.0 through 11.4.4 Drupal core versions 0.0.0 through 11.0.x Drupal core versions 0.0.0 through 11.1.x Drupal core versions 0.0.0 through 11.2.x
Description Stored Cross-site Scripting (XSS) occurs because the Layout Builder module does not sufficiently sanitize block labels in certain scenarios. This allows an attacker to inject malicious scripts that are stored and later executed in the browser of another user. Exploitation requires both the attacker and the targeted user to be using the Layout Builder editing interface.
Recommendations Update Drupal core versions 0.0.0 through 10.6.13 to a version newer than 10.6.13. Update Drupal core versions 11.3.0 through 11.3.14 to a version newer than 11.3.14. Update Drupal core versions 11.4.0 through 11.4.4 to a version newer than 11.4.4. Update Drupal core versions 0.0.0 through 11.0.x to a version newer than 11.0.x. Update Drupal core versions 0.0.0 through 11.1.x to a version newer than 11.1.x. Update Drupal core versions 0.0.0 through 11.2.x to a version newer than 11.2.x.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55805
DRUPAL-CORE-2026-012

Affected Products

Drupal Core
Drupal