CVE-2026-6365Patch(drupal / drupal)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch drupal drupal systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core: from 8.0.0 before 10.5.9, from 10.6.0 before 10.6.7, from 11.0.0 before 11.2.11, from 11.3.0 before 11.3.7.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • drupal

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
drupal

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-22: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-22: 104-1604-22
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na zranitelnost v redakčním nástroji Drupal Core, CVE-2026-6365. Tato zranitelnost typu cross-site scripting (XSS) vzniká v důsledku nedostatečné sanitizace vstupních parametrů v integraci jQuery pro AJAX modální dialogy v Drupal. Útočník může zneužít chybně ošetřené volby modálních oken k injekci škodlivého JavaScript kódu, který se následně vykoná v kontextu relace přihlášeného uživatele. Dopadem zranitelnosti může být převzetí uživatelské relace, neoprávněný přístup k citlivým informacím, jejich únik nebo další kompromitace aplikace. Zneužití je možné při zpracování škodlivě upraveného AJAX obsahu a nevyžaduje zvýšená oprávnění, pokud je útok proveden v kontextu autentizovaného uživatele. Zranitelnost se týká Drupal Core od verze 8.0.0 do 10.5.9, od 10.6.0 do 10.6.7, od 11.0.0 do 11.2.11 a od 11.3.0 do 11.3.7. 📌 Doporučujeme aktualizovat Drupal Core na verzi 10.5.9, 10.6.7, 11.2.11 a 11.3.7.

    Post summary

    The post highlights a newly disclosed XSS vulnerability (CVE‑2026‑6365) in Drupal Core, details its exploitation path and impact, and urges users to upgrade to the latest patched releases.

    02030913
    4.2K followersView on X
  • thedroptimes@thedroptimes
    Patch

    Drupal released 3 core security advisories, including critical XSS (CVE-2026-6365) in AJAX dialogs. Also includes gadget chain risk and CKEditor 5 XSS issue. Update to 10.5.9 / 10.6.7 / 11.2.11 / 11.3.7 now. https://bit.ly/4vO3AR4 #Drupal #Security #XSS #OpenSource https://t.co/DJB5p6z5GC

    Post summary

    Drupal has released core security advisories for critical XSS vulnerabilities, including CVE‑2026‑6365, and has issued updates up to versions 10.5.9, 10.6.7, 11.2.11, and 11.3.7.

    0000077
    686 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdrupaldrupal---

Explore more