CVE-2025-31675: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31675?
CVE-2025-31675 has been classified as a critical severity vulnerability due to its potential to allow Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-31675?
To fix CVE-2025-31675, update your Drupal core to the latest version: 10.4.5 or 11.1.5 and above.
What versions of Drupal are affected by CVE-2025-31675?
CVE-2025-31675 affects Drupal core versions from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, and from 11.0.0 before 11.1.5.
What kind of attack does CVE-2025-31675 facilitate?
CVE-2025-31675 facilitates Cross-Site Scripting (XSS) attacks by failing to properly neutralize user input in web pages.
Is there a patch available for CVE-2025-31675?
Yes, patches are included in the latest releases of Drupal core that address CVE-2025-31675.