CVE-2026-6367: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003
Published May 19, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 11.3.0 before 11.3.7.
Affected Software
2 affected components
Drupal Drupal Core>=11.3.0<11.3.7
Drupal Drupal>=11.3.0<11.3.7
Event History
May 19, 2026
CVE Published
via MITRE·10:28 PM
Data Sourced
via MITRE·10:28 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6367?
CVE-2026-6367 has a medium severity rating of 6.1 according to the CVSS score.
2
How do I fix CVE-2026-6367?
To fix CVE-2026-6367, you should update your Drupal core to version 11.3.7 or later.
3
What type of vulnerability is CVE-2026-6367?
CVE-2026-6367 is classified as a Cross-Site Scripting (XSS) vulnerability.
4
Which versions of Drupal are affected by CVE-2026-6367?
CVE-2026-6367 affects Drupal core versions from 11.3.0 up to, but not including, 11.3.7.
5
What can result from a successful exploit of CVE-2026-6367?
A successful exploit of CVE-2026-6367 can lead to unauthorized actions performed on behalf of users or exposure of sensitive data.