CVE-2026-3218: Responsive Favicons - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-019
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3218?
CVE-2026-3218 is classified as moderately critical due to its potential for Cross-site Scripting (XSS) exploitation.
How do I fix CVE-2026-3218?
To fix CVE-2026-3218, update the Responsive Favicons module to version 2.0.3 or higher.
What kind of vulnerability is CVE-2026-3218?
CVE-2026-3218 is an improper neutralization of input during web page generation, leading to Cross-site Scripting (XSS) vulnerabilities.
Which versions of Responsive Favicons are affected by CVE-2026-3218?
CVE-2026-3218 affects Responsive Favicons versions ranging from 0.0.0 to 2.0.2.
Is CVE-2026-3218 a widespread vulnerability?
CVE-2026-3218 can potentially affect any Drupal site using the Responsive Favicons module within the specified version range.