Unrated severityNVD Advisory· Published May 19, 2010· Updated Jun 16, 2026
CVE-2010-1976
CVE-2010-1976
Description
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:michael_nichols:taxonomy_breadcrumb:6.x-0.1:beta:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:michael_nichols:taxonomy_breadcrumb:6.x-0.1:beta:*:*:*:*:*:*
- cpe:2.3:a:michael_nichols:taxonomy_breadcrumb:6.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:michael_nichols:taxonomy_breadcrumb:6.x-1.x:dev:*:*:*:*:*:*
- Range: < 6.x-1.1
Patches
Vulnerability mechanics
References
6- drupal.org/node/758456nvdPatch
- drupal.org/node/757974nvdVendor Advisory
- secunia.com/advisories/39138nvdVendor Advisory
- drupal.org/node/757980nvd
- osvdb.org/63424nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/57446nvd
News mentions
0No linked articles in our index yet.