CVE-2026-18986: Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entity Browser (Drupal module)to a version that resolves this vulnerability.Fixed in 2.16.0Patch SA-CONTRIB-2026-094
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates an attacker needs high privileges and user interaction. The vulnerability is network-reachable and has low attack complexity.
Which deployments are affected?
Drupal Entity Browser versions from 0.0.0 through 2.16.0 are affected. The provided data does not identify any configuration-specific limitation or unaffected default configuration.
What impact can successful exploitation have?
Successful exploitation can result in low confidentiality and integrity impact across a changed scope. The CVSS vector indicates no availability impact.