CVE-2026-55805: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
Published Aug 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0., from 0.0.0 to 11.1., from 0.0.0 to 11.2..
Affected Software
1 affected component
Drupal Drupal Core>=0.0.0<=10.6.13, >=11.3.0<=11.3.14, >=11.4.0<=11.4.4, >11.0.*<11.1.*, >11.1.*<11.2.*, >11.2.*<11.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/drupal-coreto a version that resolves this vulnerability.Fixed in 10.6.13Patch SA-CORE-2026-012
Event History
Aug 25, 2026
CVE Published
via MITRE·10:22 PM
Data Sourced
via MITRE·10:22 PM
DescriptionWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Are all releases in the Drupal 11.0, 11.1, and 11.2 branches affected?
Yes. The affected-version information lists all releases in the 11.0.*, 11.1.*, and 11.2.* branches as affected.
2
Does the available information identify a fixed release or a mitigation for systems that cannot be patched immediately?
No. The provided data identifies affected versions but does not specify a fixed release, workaround, configuration mitigation, or exploitation indicators.