CVE-2026-58591: Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/colorboxto a version that resolves this vulnerability.Fixed in 2.1.5 - Upgrade
Upgrade
drupal/colorboxto a version that resolves this vulnerability.Fixed in 2.2.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SA-CONTRIB-2026-069
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58591?
CVE-2026-58591 is classified as moderately critical with a risk score of 35.
How do I fix CVE-2026-58591?
To fix CVE-2026-58591, upgrade Drupal Colorbox to version 2.1.6 or 2.2.1 or later.
What are the affected versions of Colorbox for CVE-2026-58591?
CVE-2026-58591 affects Colorbox versions from 0.0.0 to 2.1.5 and from 0.0.0 to 2.2.0.
What type of vulnerability is CVE-2026-58591?
CVE-2026-58591 is a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input.
When was CVE-2026-58591 published?
CVE-2026-58591 was published on July 10, 2026.