CVE-2026-10770: Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042
Published Jul 10, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.
Affected Software
2 affected components
CleanTalk Anti-Spam by CleanTalk>=0.0.0<=9.7.1
CleanTalk Anti-spam Drupal<9.7.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Anti-Spam by CleanTalkto a version that resolves this vulnerability.Fixed in 9.7.1Patch SA-CONTRIB-2026-042
Event History
Jul 10, 2026
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-10770?
CVE-2026-10770 has a medium severity rating of 6.1.
2
How do I fix CVE-2026-10770?
To fix CVE-2026-10770, update the Anti-Spam by CleanTalk to the latest version beyond 9.7.1.
3
What type of vulnerability is CVE-2026-10770?
CVE-2026-10770 is a Cross-Site Scripting (XSS) vulnerability.
4
Which versions of CleanTalk are affected by CVE-2026-10770?
CVE-2026-10770 affects CleanTalk Anti-Spam versions from 0.0.0 to 9.7.1.
5
What is the impact of CVE-2026-10770?
The impact of CVE-2026-10770 includes the potential for reflected XSS attacks on users.