CVE-2025-3733: baguetteBox.js - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-034
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3733?
CVE-2025-3733 is considered a medium severity vulnerability due to its potential for enabling Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-3733?
To fix CVE-2025-3733, update your Drupal baguetteBox.Js to version 2.0.4 or version 3.0.1 or later.
What versions of Drupal baguetteBox.Js are affected by CVE-2025-3733?
CVE-2025-3733 affects versions of Drupal baguetteBox.Js from 0.0.0 before 2.0.4 and from 3.0.0 before 3.0.1.
Can CVE-2025-3733 affect my website's security?
Yes, CVE-2025-3733 can compromise your website's security by allowing attackers to execute malicious scripts in the context of user sessions.
What is Cross-Site Scripting (XSS) in relation to CVE-2025-3733?
Cross-Site Scripting (XSS) in the context of CVE-2025-3733 refers to the vulnerability that allows attackers to inject arbitrary scripts into web pages viewed by users.