← Database

CVE-2026-18986

MEDIUM CVSS: 4.8 Published: 2026-09-02 Modified: 2026-09-02

Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.

Affected Platforms

Unknown

Weakness Type

CWE-79

References