PT-2026-63536 · Drupal+1 · Search Api Autocomplete+1

·

CVE-2026-16640

·

Published

2026-07-22

·

Updated

2026-08-26

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Search API Autocomplete versions 0.0.0 through 1.12.0
Description Improper neutralization of input during web page generation allows Reflected Cross-site Scripting (XSS), a flaw where malicious scripts are injected into a web page and reflected back to the user. The issue exists in a test script accessible to anonymous users that fails to sufficiently validate user input. This is partially mitigated if the web server is configured to hide warning messages from users.
Recommendations Update Search API Autocomplete to a version later than 1.12.0. As a temporary mitigation, configure the web server to disable the display of warning messages to users.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16640
DRUPAL-CONTRIB-2026-082

Affected Products

Search Api Autocomplete
Drupal Search Autocomplete