CVE Details
Basic Information
| Title | Simple XML sitemap – Moderately critical – Cross-site Scripting – SA-CONTRIB-2025-083 |
|---|---|
| Type | cve |
| Published | 2025-06-26T13:33:54.262Z |
| Last Seen |
Product Information
| Vendor | Drupal |
|---|---|
| Product | Simple XML sitemap |
| Version | 0.0.0 |
CVSS Information
| Base Score | 0.0 () |
|---|---|
| Attack Vector | |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A Cross-site Scripting (XSS) vulnerability in the Drupal Simple XML sitemap module allows attackers to inject malicious scripts into web pages. |
|---|---|
| AI Severity | Medium |
| Vendor | Drupal Community |
| Product | Simple XML sitemap |
| Affected Version | 0.0.0, versions before 4.2.2 |
Affected Products
- Drupal Simple XML sitemap 0.0.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-79 |
| Bulletin Family |
References
Description
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Drupal Simple XML sitemap allows Cross-Site Scripting (XSS). This issue affects Simple XML sitemap: from 0.0.0 before 4.2.2.