CVE-2026-6365: Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6365?
CVE-2026-6365 has a medium severity rating of 6.1 as per the CVSS 3.1 scoring.
How do I fix CVE-2026-6365?
To fix CVE-2026-6365, update your Drupal core to version 10.5.9 or later, 10.6.7 or later, or 11.2.11 or later.
What type of vulnerability is CVE-2026-6365?
CVE-2026-6365 is a Cross-site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation.
Which versions of Drupal are affected by CVE-2026-6365?
CVE-2026-6365 affects Drupal core versions from 8.0.0 before 10.5.9, 10.6.0 before 10.6.7, and 11.0.0 before 11.2.11.
What impact does CVE-2026-6365 have on users?
CVE-2026-6365 allows attackers to exploit the XSS vulnerability, potentially leading to unauthorized actions on behalf of users.