CVE-2026-13231: Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka adminfeedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka adminfeedback) versions: from 0.0.0 to 2.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Advanced Content Feedback (aka admin_feedback)to a version that resolves this vulnerability.Fixed in 2.8.0Patch SA-CONTRIB-2026-051
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13231?
The severity of CVE-2026-13231 is medium with a CVSS score of 6.1.
How do I fix CVE-2026-13231?
To fix CVE-2026-13231, update the Advanced Content Feedback module to a version later than 2.8.0.
What type of vulnerability is CVE-2026-13231?
CVE-2026-13231 is a Cross-site Scripting (XSS) vulnerability that allows for Stored XSS attacks.
Which versions of the software are affected by CVE-2026-13231?
CVE-2026-13231 affects Advanced Content Feedback (aka admin_feedback) versions from 0.0.0 to 2.8.0.
What are the implications of exploiting CVE-2026-13231?
Exploiting CVE-2026-13231 may allow an attacker to execute malicious scripts in the context of the user's browser.