CVE-2026-6365

CVE-2026-6365: Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001

Vendor Drupal
Product Drupal core
Weakness CWE-79 · XSS
Published May 19, 2026
Last update May 20, 2026

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

Explanation of Vulnerability in Simple Terms

02Summary

Drupal core versions 8.0.0 through 10.5.8 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in users' browsers when they view affected pages. The vulnerability's exact attack vector and required privileges are not fully documented in available metadata. Update to Drupal 10.5.9 or later to resolve this issue.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that run in users' browsers when they view affected pages.

Potential impact on your site

04Site Impact

Users visiting affected pages may have their sessions hijacked, credentials stolen, or site functionality compromised.

Conditions required to exploit

05Prerequisites

Ability to submit or modify content on the site; exact privilege level unknown due to missing CVSS data.

Key dates

06Disclosure timeline

May 19, 2026 CVE published
May 20, 2026 Record updated

Related vulnerabilities

08Related CVE