CVE-2025-7716: Real-time SEO for Drupal - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-091
Published Jul 21, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS).This issue affects Real-time SEO for Drupal: from 2.0.0 before 2.2.0.
Affected Software
2 affected components
Drupal Real-time SEO for Drupal>=2.0.0<2.2.0
Real-time Seo Project Real-time Seo Drupal>=8.x-2.0<=8.x-2.2
Event History
Jul 21, 2025
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-7716?
The CVE-2025-7716 vulnerability is classified as a high severity Cross-Site Scripting (XSS) issue.
2
How do I fix CVE-2025-7716?
To fix CVE-2025-7716, upgrade the Real-time SEO for Drupal module to version 2.2.0 or later.
3
Which versions of Real-time SEO for Drupal are affected by CVE-2025-7716?
CVE-2025-7716 affects Real-time SEO for Drupal versions from 2.0.0 up to, but not including, 2.2.0.
4
What type of vulnerability is CVE-2025-7716?
CVE-2025-7716 is a Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input.
5
Who is affected by CVE-2025-7716?
Any user or organization using Real-time SEO for Drupal versions 2.0.0 to 2.1.x is affected by CVE-2025-7716.