4.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1.
Basic Information
ID
CVE-2026-0947
Source
drupal
Published
Feb 4, 2026 at 20:25
Modified
Feb 4, 2026 at 21:24
Affected Product
Vendor
Drupal
Product
AT Internet Piano Analytics
Version
0.0.0
Affected Versions
Drupal AT Internet Piano Analytics 0.0.0
Drupal AT Internet Piano Analytics 2.0.0
Drupal AT Internet Piano Analytics 2.0.0