CVE-2026-3213: Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Cross-Site Scripting (XSS).This issue affects Anti-Spam by CleanTalk: from 0.0.0 before 9.7.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3213?
CVE-2026-3213 has been classified as moderately critical due to its potential for cross-site scripting (XSS) attacks.
How does CVE-2026-3213 affect the Anti-Spam by CleanTalk module?
CVE-2026-3213 allows for an improper neutralization of input during web page generation, enabling cross-site scripting vulnerabilities in the Anti-Spam by CleanTalk module.
What versions of Anti-Spam by CleanTalk are impacted by CVE-2026-3213?
CVE-2026-3213 affects all versions of Anti-Spam by CleanTalk from 0.0.0 up to, but not including, 9.7.0.
How can I fix CVE-2026-3213 in my Drupal site?
To mitigate CVE-2026-3213, update the Anti-Spam by CleanTalk module to the latest available version.
What kind of attacks can CVE-2026-3213 enable?
CVE-2026-3213 can enable various cross-site scripting (XSS) attacks that may compromise user data and site security.