Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
Project: Drupal core Date: 2026-July-15 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Cross-site scripting Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.* CVE IDs: CVE-2026-55805 Description: The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability. This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface. Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13 . Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-life. Reported By: haii haii (hai27ii2o) Fixed By: danielveza Lee Rowlands (larowlan) of the Drupal Security Team Mingsong (mingsong) provisional member of the Drupal Security Team James Gilliland (neclimdul) of the Drupal Security Team Coordinated By: Greg Knaddison (greggles) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Dave Long (longwave) of the Drupal Security Team Jess (xjm) of the Drupal Security Team
CSIRTS triage
- What
- The Layout Builder module doesn't sufficiently sanitize block labels, leading to a cross-site scripting (XSS) vulnerability.
- Who is affected
- Deployments of Drupal core versions listed above that use the Layout Builder editing interface are affected.
- Urgency
- Remediation is urgent due to the critical severity of the vulnerability, although exploitation requires specific conditions.
- Action
- Update to Drupal 11.4.4 for 11.4.x users, 11.3.14 for 11.3.x users, or upgrade to the latest version of Drupal 10.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Drupal core
Get an email when a new Drupal core advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.drupal.org/sa-core-2026-012
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55805 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Drupal Core: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Drupal (July 16, 2026)cert-fr-avis
Recent advisories for Drupal core -
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Drupal Core: Multiple vulnerabilitiescert-bund · 2026-07-16
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011drupal · 2026-07-15
- criticalDrupal core - Moderately critical - Information disclosure - SA-CORE-2026-010drupal · 2026-07-15
- critical[UPDATE] [critical] Drupal Core: Multiple vulnerabilitiescert-bund · 2026-07-13
- mediumCVE-2026-55808: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd · 2026-07-10
- lowCVE-2026-55807: Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Requ…nvd · 2026-07-10
More from Drupal Security Advisories
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-0112026-07-15
- criticalDrupal core - Moderately critical - Information disclosure - SA-CORE-2026-0102026-07-15
- criticalDrupal core - Moderately critical - Improper validation - SA-CORE-2026-0092026-06-17
- criticalDrupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-0082026-06-17
- criticalDrupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-0072026-06-17