6.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
Basic Information
ID
CVE-2026-6365
Source
drupal
Published
May 19, 2026 at 22:27
Modified
May 20, 2026 at 13:35
Affected Product
Vendor
Drupal
Product
Drupal core
Version
8.0.0
Affected Versions
Drupal Drupal core 8.0.0
Drupal Drupal core 10.6.0
Drupal Drupal core 11.0.0
Drupal Drupal core 11.3.0
Drupal Drupal core 10.6.0
Drupal Drupal core 11.0.0
Drupal Drupal core 11.3.0