CVE-2026-0946: AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003
Published Feb 4, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1.
Affected Software
2 affected components
drupal/at-internet-smarttag<1.0.1
Bordeaux-metropole At Internet Smarttag Drupal<1.0.1
Event History
Feb 4, 2026
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0946?
CVE-2026-0946 is rated as moderately critical due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2026-0946?
To fix CVE-2026-0946, upgrade the AT Internet SmartTag module to the latest version beyond 1.0.1.
3
What type of vulnerability is CVE-2026-0946?
CVE-2026-0946 is a Cross-Site Scripting (XSS) vulnerability.
4
Which software is affected by CVE-2026-0946?
CVE-2026-0946 affects the AT Internet SmartTag module for Drupal versions up to 1.0.1.
5
What can attackers do with CVE-2026-0946?
Attackers can exploit CVE-2026-0946 to execute arbitrary JavaScript in the context of the user's browser through XSS.