Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-009 |
|
History
Wed, 25 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1. | |
| Title | Quick Edit - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-009 | |
| Weaknesses | CWE-79 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-03-25T15:20:53.201Z
Reserved: 2026-02-11T15:48:44.422Z
Link: CVE-2026-2348
No data.
Status : Received
Published: 2026-03-25T16:16:21.517
Modified: 2026-03-25T16:16:21.517
Link: CVE-2026-2348
No data.
OpenCVE Enrichment
No data.
Weaknesses