PT-2026-69023 · Drupal+1 · Entity Browser+1

·

CVE-2026-18986

·

Published

2026-08-05

·

Updated

2026-09-02

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Entity Browser versions 0.0.0 through 2.16.0
Description Stored cross-site scripting (XSS) occurs because the module does not sufficiently sanitize tab titles. This allows an attacker to insert HTML with specific attributes on a page displaying an entity browser. Cross-site scripting is a flaw where malicious scripts are injected into trusted websites.
Recommendations Update Drupal Entity Browser to a version later than 2.16.0.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18986
DRUPAL-CONTRIB-2026-094

Affected Products

Entity Browser
Drupal/Entity Browser