What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS).
This issue affects Obfuscate: from 0.0.0 before 2.0.2.
Explanation of Vulnerability in Simple Terms
02Summary
The Obfuscate module for Drupal contains a cross-site scripting (XSS) vulnerability in versions before 2.0.2. An attacker can inject malicious scripts that execute in the browsers of site visitors or administrators. The vulnerability exists in how the module processes or displays user-controlled input without proper sanitization. Update to version 2.0.2 or later to resolve this issue.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs in visitors' browsers, potentially stealing session tokens or admin credentials.
Potential impact on your site
04Site Impact
Visitors and admins could have their sessions hijacked or credentials stolen if they interact with injected content.
Conditions required to exploit
05Prerequisites
Depends on module configuration; may require authenticated access or user interaction (victim visiting a crafted page).
Key dates
06Disclosure timeline
May 19, 2026
CVE published
May 20, 2026
Record updated