CVE-2026-81201: Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116
Published Sep 2, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.
Affected Software
4 affected components
Drupal Monster Menus>=0.0.0<=9.5.3
Monster Menus Project Monster Menus Drupal>=6.x-6.19<=6.x-6.64
Monster Menus Project Monster Menus Drupal>=7.x-1.0<=7.x-1.34
Monster Menus Project Monster Menus Drupal>=9.0.0<9.5.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Monster Menus (Drupal module)to a version that resolves this vulnerability.Fixed in 9.5.3Patch SA-CONTRIB-2026-116
Event History
Sep 2, 2026
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which installations fall within the affected version range?
Drupal Monster Menus versions from 0.0.0 through 9.5.3 are affected.
2
Is the injected content limited to the attacker’s own session?
No. The issue is identified as stored XSS, meaning malicious input can be retained and later generated in web pages.