CVE-2026-3528: Calculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023
Published Mar 26, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scripting (XSS).This issue affects Calculation Fields: from 0.0.0 before 1.0.4.
Affected Software
2 affected components
Drupal Calculation Fields>=0.0.0<1.0.4
Joaopaulocdev Calculation Fields Drupal<1.0.4
Event History
Mar 26, 2026
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3528?
CVE-2026-3528 is considered moderately critical due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2026-3528?
To remediate CVE-2026-3528, update the Calculation Fields module to version 1.0.5 or later.
3
What type of vulnerability is CVE-2026-3528?
CVE-2026-3528 is categorized as a Cross-Site Scripting (XSS) vulnerability.
4
Which versions of Calculation Fields are affected by CVE-2026-3528?
CVE-2026-3528 affects all versions of Calculation Fields from 0.0.0 up to 1.0.4.
5
What is the impact of CVE-2026-3528 on Drupal websites?
The impact of CVE-2026-3528 can allow attackers to execute arbitrary scripts in the context of users' browsers, potentially leading to data theft or session hijacking.