CVE-2026-55805

CVE-2026-55805: Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012

Vendor Drupal
Product Drupal core
Weakness CWE-79 · XSS
Published August 25, 2026
Last update August 26, 2026

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 26, 2026 Record updated

Related vulnerabilities

04Related CVE