
CVE-2026-4929 Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include … https://www.cve.org/CVERecord?id=CVE-2026-4929
Post summary
This brief notice confirms the existence of CVE‑2026‑4929, describing it as an XSS vulnerability in Drupal 7 caused by improper output escaping, and points to the official CVE record, with no mention of PoC, exploit code, or remediation.
