Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.
References
| Link | Resource |
|---|---|
| https://www.drupal.org/sa-contrib-2026-094 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-02 13:17
Updated : 2026-09-08 14:43
NVD link : CVE-2026-18986
Mitre link : CVE-2026-18986
CVE.ORG link : CVE-2026-18986
JSON object : View
Products Affected
entity_browser_project
- entity_browser
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
