CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011

criticalCVE-2026-15917
Project: Drupal core Date: 2026-July-15 Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All Vulnerability: Cross-site scripting Affected versions: >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.2.* CVE IDs: CVE-2026-15917 Description: Drupal core 11.2 and above integrate the HTMX JavaScript library. Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability. The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes. Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 Drupal 10 core is not affected. However, certain contributed modules may be affected, so a Drupal 10.6 fix is included as hardening. Drupal 8 and Drupal 9 have both reached end-of-life. Reported By: Pierre Rudloff (prudloff) of the Drupal Security Team Fixed By: Shawn Duncan (fathershawn) Pierre Rudloff (prudloff) of the Drupal Security Team Coordinated By: catch (catch) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Dave Long (longwave) of the Drupal Security Team Jess (xjm) of the Drupal Security Team

CSIRTS triage

vendor: Drupalproduct: Drupal coreCross-site scriptingaffected: >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.2.*
What
Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, leading to a cross-site scripting (XSS) vulnerability.
Who is affected
Deployments of Drupal core versions 11.2 and above that integrate the HTMX JavaScript library are affected.
Urgency
Remediation is urgent due to the critical severity of the vulnerability, although exploitation requires specific conditions.
Action
Update to Drupal 11.4.4 for 11.4.x users, 11.3.14 for 11.3.x users, or upgrade to the latest version of Drupal 10.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Drupal core

Get an email when a new Drupal core advisory drops — max one per day, one-click unsubscribe.

Details

Source
Drupal Security Advisories (INTL · vendor-psirt · site)
Severity
critical
Published
2026-07-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.drupal.org/sa-core-2026-011

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-15917coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Drupal core -

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Drupal Security Advisories