CVE-2025-6677: Paragraphs table - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-084
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs table allows Cross-Site Scripting (XSS).This issue affects Paragraphs table: from 2.0.0 before 2.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6677?
CVE-2025-6677 has been classified as a medium severity vulnerability due to its ability to allow Cross-Site Scripting (XSS).
How do I fix CVE-2025-6677?
To fix CVE-2025-6677, upgrade Drupal Paragraphs to version 2.0.5 or later.
Which versions of Drupal Paragraphs are affected by CVE-2025-6677?
CVE-2025-6677 affects Drupal Paragraphs versions between 2.0.0 and 2.0.4 inclusive.
What type of vulnerability is CVE-2025-6677?
CVE-2025-6677 is a Cross-Site Scripting (XSS) vulnerability that arises from improper neutralization of input during web page generation.
Can CVE-2025-6677 impact my website's security?
Yes, CVE-2025-6677 can impact your website's security by allowing attackers to inject malicious scripts into web pages viewed by users.