
CVE-2026-4093 In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token… https://www.cve.org/CVERecord?id=CVE-2026-4093
Post summary
This post discloses a stored XSS vulnerability (CVE‑2026‑4093) in Drupal 7's Term Reference Tree module, detailing the affected vectors but offering no PoC, exploit code, patch, or evidence of active exploitation.
