CVE-2026-15917: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Published Aug 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2..
Affected Software
1 affected component
Drupal Drupal Core>=11.3.0<=11.3.14, >=11.4.0<=11.4.4, >=0.0.0<11.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal coreto a version that resolves this vulnerability.Patch SA-CORE-2026-011
Event History
Aug 25, 2026
CVE Published
via MITRE·10:22 PM
Data Sourced
via MITRE·10:22 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an authenticated Drupal account to exploit this issue?
No privileges are required according to the CVSS vector. Exploitation is network-reachable but requires user interaction and has high attack complexity.
2
What is the expected security impact if exploitation succeeds?
The CVSS vector indicates low-impact confidentiality and integrity effects, with no availability impact. The scope is marked changed.