CVE-2025-3057: Drupal core - Critical - Cross site scripting - SA-CORE-2025-001
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3057?
CVE-2025-3057 has a severity rating of Medium due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-3057?
To fix CVE-2025-3057, update your Drupal core to version 10.4.3, 11.0.12, or later.
Which versions of Drupal are affected by CVE-2025-3057?
CVE-2025-3057 affects Drupal core versions from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, and from 11.0.0 before 11.0.12.
What type of vulnerabilities does CVE-2025-3057 exploit?
CVE-2025-3057 exploits vulnerabilities related to Improper Neutralization of Input During Web Page Generation, specifically leading to Cross-Site Scripting (XSS).
What should I do if I cannot update my Drupal installation to fix CVE-2025-3057?
If you cannot update, consider implementing web application firewalls and input validation measures as temporary mitigations for CVE-2025-3057.