CVE-2025-31682: Google Tag - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-011
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS). This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31682?
CVE-2025-31682 has been rated as a critical severity due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-31682?
To fix CVE-2025-31682, update the Drupal Google Tag module to version 1.8.0 or 2.0.8 or later.
Which versions of Drupal Google Tag are affected by CVE-2025-31682?
CVE-2025-31682 affects Drupal Google Tag versions from 0.0.0 up to 1.8.0 and from 2.0.0 up to 2.0.8.
What type of vulnerability is CVE-2025-31682?
CVE-2025-31682 is classified as a Cross-Site Scripting (XSS) vulnerability.
Can exploitation of CVE-2025-31682 lead to data theft?
Yes, exploitation of CVE-2025-31682 can lead to unauthorized access and potential data theft via XSS attacks.