Medium severity4.4NVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-13981
CVE-2025-13981
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS).This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.7, from 1.1.0 before 1.1.7, from 1.2.0 before 1.2.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: from 0.0.0 before 1.0.7, from 1.1.0 before 1.1.7, from 1.2.0 before 1.2.4
- cpe:2.3:a:artificial_intelligence_project:artificial_intelligence:*:*:*:*:*:drupal:*:*Range: <1.0.7
- Range: <1.0.7,>=1.1.0,<1.1.7,>=1.2.0,<1.2.4Package: https://wordpress.org/plugins/ai
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2025-119nvdVendor Advisory
News mentions
0No linked articles in our index yet.